A missing authentication vulnerability has been identified in ramon-victor freegpt-webui up to commit 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. The vulnerability resides in the _conversation function within server/backend.py, part of the Backend Conversation API component. Manipulation of the 'model' argument allows bypassing authentication entirely. The attack can be launched remotely without user interaction. A public exploit has been disclosed and is available for use. The product follows a rolling release model, meaning no specific version numbers are available for affected or patched releases. The maintainer no longer supports this product, leaving users without an official fix. The vulnerability has been catalogued in VulDB and NVD databases.