Metrics
Affected Vendors & Products
Tue, 05 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 02 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatgptnextweb
Chatgptnextweb nextchat |
|
| Vendors & Products |
Chatgptnextweb
Chatgptnextweb nextchat |
Sat, 02 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | ChatGPTNextWeb NextChat actions.ts addMcpServer improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-05-02T15:00:13.502Z
Updated: 2026-05-04T13:09:05.752Z
Reserved: 2026-05-01T16:34:02.930Z
Link: CVE-2026-7644
Updated: 2026-05-04T13:08:39.107Z
Status : Deferred
Published: 2026-05-02T15:16:14.373
Modified: 2026-05-05T19:15:06.200
Link: CVE-2026-7644
No data.
ReportizFlow