Vendor
NextChat versions 2.15.8 through 2.16.1 are vulnerable to credential theft due to weak URL validation in the proxy endpoint, allowing attackers to exfiltrate the server's OpenAI API key.