CVE-2026-7643

Source
https://cve.org/CVERecord?id=CVE-2026-7643
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7643.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-7643
Published
2026-05-02T14:45:12.877Z
Modified
2026-07-15T01:49:12.730297089Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
ChatGPTNextWeb NextChat API Endpoint Next.js cross-domain policy
Details

A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-346",
        "CWE-942"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7643.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/chatgptnextweb/nextchat

Affected ranges

Type
GIT
Repo
https://github.com/chatgptnextweb/nextchat
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "2.16.0"
        },
        {
            "last_affected": "2.16.0"
        },
        {
            "introduced": "2.16.1"
        },
        {
            "last_affected": "2.16.1"
        }
    ]
}

Affected versions

2.*
2.16.0
2.16.1
v2.*
v2.16.0
v2.16.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7643.json"