CVE-2026-85703: ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resources
A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue can be exploited remotely and requires no privileges or user interaction according to the supplied vector. Exploitation involves manipulating the getJailbreak function in server/backend.py within the Jailbreak Mode component.
How likely is exploitation in practice?
An exploit has been published and may be used. The vulnerability is rated medium severity, with potential integrity and availability impact.
Which deployments should be prioritized for investigation?
Prioritize unsupported ramon-victor/freegpt-webui deployments using revisions up to commit 098db3dfeb41555c2ca9269df0f13e10ec1c35dc, particularly where Jailbreak Mode is exposed remotely. The issue only affects products no longer supported by the maintainer.
Can affected and fixed versions be identified from release numbers?
No. The product uses a rolling release model, and version information for affected or updated releases is unavailable; assess the source revision and the presence of the affected getJailbreak implementation instead.