Impact
The vulnerability is a race condition in the getJailbreak function of freegpt-webui’s Jailbreak Mode implementation. Manipulating the request to trigger the race can allow an attacker to exploit the timing flaw to gain elevated privileges or execute code remotely. The description notes that a remote attack is possible, that it requires a significant level of complexity, and that the exploit is considered difficult to execute. No confirmed post‑exploitation capabilities are listed, but the presence of a race condition that can be triggered remotely indicates a potential for unauthorized control over the web interface.
Affected Systems
The affected product is freegpt-webui by ramon‑victor. The version information is not available because the project uses rolling releases, and the description indicates that only unsupported releases are impacted.
Risk and Exploitability
The CVSS score of 6.3 places the vulnerability in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The impact is influenced by the fact that the product is no longer supported, which reduces the likelihood of a vendor release. Attackers must overcome a difficult exploit path, but the public release of the exploit script raises concern. Overall, the risk is moderate, with potential for remote code execution if the race condition is successfully abused.
OpenCVE Enrichment