CVE-2026-85704
Received Received - Intake

Race Condition in FreeGPT WebUI Jailbreak Mode

Vulnerability report for CVE-2026-85704, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulDB

Description

A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ramon-victor freegpt-webui to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a race condition in the ramon-victor freegpt-webui software, specifically in the getJailbreak function of server/config.py. A race condition occurs when the system's behavior depends on the timing of events, which can lead to unexpected results. The flaw allows remote attackers to exploit this condition, though the attack is complex and requires a high level of skill.

Impact Analysis

The impact of this vulnerability is limited due to its high exploit complexity and low CVSS scores. It primarily affects the availability of the service (A:L in CVSS v3.1), meaning it could cause disruptions but is unlikely to lead to data breaches or unauthorized access. The exploit has been publicly released, increasing the risk of attacks.

Mitigation Strategies

Since the product is no longer supported and the vulnerability affects an unsupported component, the only reliable mitigation is to discontinue use of ramon-victor freegpt-webui entirely. Isolate any systems running this software from your network to prevent potential exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85704. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart