SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85702

HIGH · CVSS 7.3 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in the ramon-victor freegpt-webui affects the Backend Conversation API, specifically the _conversation function in server/backend.py, allowing for remote exploitation due to missing authentication. This could enable unauthorized access and manipulation of conversations, posing a significant risk to data integrity and user privacy. Organizations using unsupported versions of this product should prioritize immediate remediation to mitigate potential attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85702
Severity
HIGH
CVSS
7.3
EPSS
0.39%

Original NVD Description

A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. This vulnerability only affects products that are no longer supported by the maintainer.