在 ramon-victor 的 freegpt-webui 项目中检测到一个安全漏洞,影响范围覆盖至提交哈希 098db3dfeb41555c2ca9269df0f13e10ec1c35dc。受影响的是组件“Backend Conversation API”中文件 server/backend.py 内的 函数。对参数 的操纵会导致认证机制缺失(missing authentication)。该攻击可通过远程发起。此漏洞的利用方法已公开披露,可能已被利用。 该产品基于滚动发布(rolling release)机制
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ramon-victor | freegpt-webui | 098db3dfeb41555c2ca9269df0f13e10ec1c35dc |
cpe:2.3:a:ramon-victor:freegpt-webui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85703 | 6.5 MEDIUM | ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resources |
| CVE-2026-85701 | 5.3 MEDIUM | ramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing |
| CVE-2026-85704 | 3.7 LOW | ramon-victor freegpt-webui Jailbreak Mode config.py getJailbreak race condition |
No comments yet