๐Ÿ” CVE Alert

CVE-2026-85701

MEDIUM 5.3

ramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authentication

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer.

CWE CWE-306 CWE-287
Vendor ramon-victor
Product freegpt-webui
Published Sep 4, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for ramon-victor freegpt-webui

Be the first to know when new medium vulnerabilities affecting ramon-victor freegpt-webui are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ramon-victor / freegpt-webui
098db3dfeb41555c2ca9269df0f13e10ec1c35dc

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/398799 vuldb.com: https://vuldb.com/vuln/398799/cti vuldb.com: https://vuldb.com/cve/CVE-2026-85701 vuldb.com: https://vuldb.com/submit/895266 gist.github.com: https://gist.github.com/Galaxync/4e91898128de8fffbaf893fb1f9d4272

Credits

๐Ÿ” Galaxyn (VulDB User)