<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>NextChat - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/nextchat/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 30 Aug 2026 17:11:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/nextchat/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper URL Validation in NextChat Proxy Endpoint</title><link>https://feed.craftedsignal.io/briefs/2026-08-nextchat-url-validation/</link><pubDate>Sun, 30 Aug 2026 17:11:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-nextchat-url-validation/</guid><description>NextChat versions 2.15.8 through 2.16.1 are vulnerable to credential theft due to weak URL validation in the proxy endpoint, allowing attackers to exfiltrate the server's OpenAI API key.</description><content:encoded>&lt;p>NextChat versions 2.15.8 through 2.16.1 contain an improper URL validation vulnerability located within the application's proxy endpoint. The flaw stems from the application utilizing weak substring matching rather than proper hostname parsing when validating the 'x-base-url' HTTP header.&lt;/p>
&lt;p>An attacker can leverage this logic error by providing a crafted URL that contains the string 'api.openai.com' as a substring. This bypasses the intended security controls, causing the NextChat server to route requests to an attacker-controlled destination while including the server's sensitive OpenAI API key within the Authorization header. This vulnerability enables unauthorized access to and potential exfiltration of the organization's OpenAI API credentials.&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>