<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Freegpt-Webui (Up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/freegpt-webui-up-to-098db3dfeb41555c2ca9269df0f13e10ec1c35dc/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 23:27:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/freegpt-webui-up-to-098db3dfeb41555c2ca9269df0f13e10ec1c35dc/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in freegpt-webui Backend Conversation API</title><link>https://feed.craftedsignal.io/briefs/2026-09-freegpt-webui-vulnerability/</link><pubDate>Fri, 04 Sep 2026 23:27:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-freegpt-webui-vulnerability/</guid><description>An unauthenticated remote code execution or unauthorized access vulnerability in the freegpt-webui Backend Conversation API allows attackers to bypass authentication via input manipulation.</description><content:encoded><![CDATA[<p>A security vulnerability has been identified in the freegpt-webui application, specifically affecting the Backend Conversation API component. The issue resides within the _conversation function located in server/backend.py. Remote attackers can exploit this flaw by manipulating the 'model' argument, which results in a complete bypass of authentication mechanisms. This vulnerability, tracked as CVE-2026-85702, impacts the software up to commit hash 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Because the project follows a rolling release model and the vulnerability is limited to unsupported versions, defenders must audit their instances to ensure they are not running legacy codebases. The public disclosure of the exploit code increases the risk of exploitation by remote threat actors targeting exposed web interfaces.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-85702 allows an unauthenticated remote attacker to interact with the backend API without proper authorization. This may lead to unauthorized access to conversation history, unauthorized utilization of AI model resources, or further compromise of the underlying application server, depending on the server's configuration and backend permissions.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Audit web infrastructure to identify and decommission any instances of freegpt-webui running the vulnerable commit hash or older versions.</li>
<li>Implement strict ingress filtering for web UI components to ensure that only authorized administrative networks can communicate with the backend API endpoints.</li>
<li>Monitor web application logs for unexpected POST requests to API endpoints that do not correspond to authenticated user sessions.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>