CVE-2026-7643
Last modified
CVE-2026-7643 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7643?
How severe is CVE-2026-7643?
How do I fix CVE-2026-7643?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7637The Boost plugin for WordPress is vulnerable to PHP Object I…9.8
- CVE-2026-7638The App Builder – Create Native Android & iOS Apps On The Fl…5.3
- CVE-2026-7639Software installed and run as a non-privileged user may cond…7.8
- CVE-2026-7640The WP Customer Area plugin for WordPress is vulnerable to S…6.4
- CVE-2026-7641The Import and export users and customers plugin for WordPre…8.8
- CVE-2026-7642A vulnerability was detected in pskill9 website-downloader u…6.3
- CVE-2026-7644A vulnerability has been found in ChatGPTNextWeb NextChat up…7.3
- CVE-2026-7645A vulnerability was found in ruvnet sublinear-time-solver 1.…6.5
- CVE-2026-7646IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read a…6.5
- CVE-2026-7647The Profile Builder Pro plugin for WordPress is vulnerable t…8.1
- CVE-2026-7648The LearnPress – WordPress LMS Plugin for Create and Sell On…4.3
- CVE-2026-7649The ARMember – Membership Plugin, Content Restriction, Membe…7.5
Are you affected by CVE-2026-7643?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
