CVE-2026-7643: A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cr...
Added to the CISA Known Exploited Vulnerabilities catalog on 02 May 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 4.3.
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The exploit has been ...
Required action: Review and patch if applicable to your AI infrastructure.