CVE-2026-7644: ChatGPTNextWeb NextChat actions.ts addMcpServer improper authorization
A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7644?
CVE-2026-7644 is classified as a high severity vulnerability due to its potential for improper authorization leading to unauthorized access.
How do I fix CVE-2026-7644?
To fix CVE-2026-7644, update ChatGPTNextWeb NextChat to version 2.16.2 or later, where the authorization issue has been resolved.
What is the impact of CVE-2026-7644 exploitation?
Exploitation of CVE-2026-7644 can allow unauthorized users to perform actions that should require higher privileges.
Which versions of ChatGPTNextWeb NextChat are affected by CVE-2026-7644?
CVE-2026-7644 affects all versions of ChatGPTNextWeb NextChat up to and including 2.16.1.
Is remote exploitation possible for CVE-2026-7644?
Yes, CVE-2026-7644 allows for remote exploitation, making it crucial for users to promptly apply patches.