A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1 and classified as critical. Affected is the function addMcpServer of the file app/mcp/actions.ts. The manipulation leads to improper authorization.

This vulnerability is referenced as CVE-2026-7644. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.