No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 02 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatgptnextweb
Chatgptnextweb nextchat |
|
| Vendors & Products |
Chatgptnextweb
Chatgptnextweb nextchat |
Sat, 02 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | ChatGPTNextWeb NextChat actions.ts addMcpServer improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-02T15:00:13.502Z
Reserved: 2026-05-01T16:34:02.930Z
Link: CVE-2026-7644
No data.
Status : Received
Published: 2026-05-02T15:16:14.373
Modified: 2026-05-02T15:16:14.373
Link: CVE-2026-7644
No data.
OpenCVE Enrichment
Updated: 2026-05-02T16:30:46Z