CVE-2026-85702 Details
Description
A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. This vulnerability only affects products that are no longer supported by the maintainer.
A vulnerability allowing unauthenticated access to the Backend Conversation API has been identified in ramon-victor freegpt-webui versions prior to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. The vulnerability arises because the conversation endpoint lacks authentication and authorization checks, allowing any anonymous user to access the AI proxy service without restrictions. Additionally, the 'model' parameter is not validated against a server-configured whitelist, enabling misuse of AI provider resources, including expensive models like gpt-4, and the activation of jailbreak modes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Galaxync/15cb5d1bf6ab110f0cba91664ed511dd | CISA-ADP | ExploitTechnical Description |
| https://gist.github.com/Galaxync/15cb5d1bf6ab110f0cba91664ed511dd | [email protected] | ExploitTechnical Description |
| https://vuldb.com/cve/CVE-2026-85702 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/895267 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/398805 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/398805/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ramon-victor freegpt-webui | <= 098db3dfeb41555c2ca9269df0f13e10ec1c35dc |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion