{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/freegpt-webui-up-to-098db3dfeb41555c2ca9269df0f13e10ec1c35dc/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ramon-victor:freegpt-webui:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-85702"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["freegpt-webui (up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ramon-victor"],"content_html":"\u003cp\u003eA security vulnerability has been identified in the freegpt-webui application, specifically affecting the Backend Conversation API component. The issue resides within the _conversation function located in server/backend.py. Remote attackers can exploit this flaw by manipulating the 'model' argument, which results in a complete bypass of authentication mechanisms. This vulnerability, tracked as CVE-2026-85702, impacts the software up to commit hash 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Because the project follows a rolling release model and the vulnerability is limited to unsupported versions, defenders must audit their instances to ensure they are not running legacy codebases. The public disclosure of the exploit code increases the risk of exploitation by remote threat actors targeting exposed web interfaces.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-85702 allows an unauthenticated remote attacker to interact with the backend API without proper authorization. This may lead to unauthorized access to conversation history, unauthorized utilization of AI model resources, or further compromise of the underlying application server, depending on the server's configuration and backend permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit web infrastructure to identify and decommission any instances of freegpt-webui running the vulnerable commit hash or older versions.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering for web UI components to ensure that only authorized administrative networks can communicate with the backend API endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for unexpected POST requests to API endpoints that do not correspond to authenticated user sessions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T23:27:56Z","date_published":"2026-09-04T23:27:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-freegpt-webui-vulnerability/","summary":"An unauthenticated remote code execution or unauthorized access vulnerability in the freegpt-webui Backend Conversation API allows attackers to bypass authentication via input manipulation.","title":"Authentication Bypass in freegpt-webui Backend Conversation API","url":"https://feed.craftedsignal.io/briefs/2026-09-freegpt-webui-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Freegpt-Webui (Up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc)","version":"https://jsonfeed.org/version/1.1"}