No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 02 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatgptnextweb
Chatgptnextweb nextchat |
|
| Vendors & Products |
Chatgptnextweb
Chatgptnextweb nextchat |
Sat, 02 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | ChatGPTNextWeb NextChat API Endpoint Next.js cross-domain policy | |
| Weaknesses | CWE-346 CWE-942 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-02T14:45:12.877Z
Reserved: 2026-05-01T16:33:59.113Z
Link: CVE-2026-7643
No data.
Status : Received
Published: 2026-05-02T15:16:14.203
Modified: 2026-05-02T15:16:14.203
Link: CVE-2026-7643
No data.
OpenCVE Enrichment
Updated: 2026-05-02T16:30:46Z