{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nextchat-2.15.8-2.16.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nextchat:nextchat:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82639"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NextChat (2.15.8-2.16.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["NextChat"],"content_html":"\u003cp\u003eNextChat versions 2.15.8 through 2.16.1 contain an improper URL validation vulnerability located within the application's proxy endpoint. The flaw stems from the application utilizing weak substring matching rather than proper hostname parsing when validating the 'x-base-url' HTTP header.\u003c/p\u003e\n\u003cp\u003eAn attacker can leverage this logic error by providing a crafted URL that contains the string 'api.openai.com' as a substring. This bypasses the intended security controls, causing the NextChat server to route requests to an attacker-controlled destination while including the server's sensitive OpenAI API key within the Authorization header. This vulnerability enables unauthorized access to and potential exfiltration of the organization's OpenAI API credentials.\u003c/p\u003e\n","date_modified":"2026-08-30T17:11:12Z","date_published":"2026-08-30T17:11:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nextchat-url-validation/","summary":"NextChat versions 2.15.8 through 2.16.1 are vulnerable to credential theft due to weak URL validation in the proxy endpoint, allowing attackers to exfiltrate the server's OpenAI API key.","title":"Improper URL Validation in NextChat Proxy Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-nextchat-url-validation/"}],"language":"en","title":"CraftedSignal Threat Feed - NextChat (2.15.8-2.16.1)","version":"https://jsonfeed.org/version/1.1"}