CVE-2026-85703
Received Received - Intake

Remote Resource Allocation in FreeGPT WebUI

Vulnerability report for CVE-2026-85703, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulDB

Description

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ramon-victor freegpt-webui to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the ramon-victor freegpt-webui software, specifically in the getJailbreak function of server/backend.py. It allows remote attackers to manipulate the system to cause resource exhaustion. The flaw exists in versions up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc and has been publicly disclosed. The software follows a rolling release model, so version details for affected updates are unavailable.

Detection Guidance

This vulnerability affects the function getJailbreak in server/backend.py of freegpt-webui. Detection requires checking for the presence of this file and function in the application. No specific commands are provided in the context to detect this issue.

Impact Analysis

If exploited, this vulnerability could lead to denial-of-service conditions by consuming excessive system resources. Attackers could remotely trigger the flaw, potentially degrading or crashing the application. Since the product is no longer supported, patches may not be available.

Compliance Impact

This vulnerability does not directly impact compliance with standards like GDPR or HIPAA as it relates to a specific software component (freegpt-webui) and involves resource allocation issues rather than data privacy or security breaches.

Mitigation Strategies

Immediately stop using ramon-victor freegpt-webui as it is no longer supported and contains a remotely exploitable flaw. Remove or isolate the application from your network to prevent potential resource allocation attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85703. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart