CVE-2026-7644: A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remot...

Added to the CISA Known Exploited Vulnerabilities catalog on 02 May 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 7.3.

A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be us...

Required action: Review and patch if applicable to your AI infrastructure.