GHSA-rhg8-4whm-xj7wMediumCVSS 7.3
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the...
🔗 CVE IDs covered (1)
📋 Description
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-105238
- https://github.com/ChatGPTNextWeb/NextChat/issues/6813
- https://github.com/ChatGPTNextWeb/NextChat/pull/6884
- https://github.com/ChatGPTNextWeb/NextChat
- https://vuldb.com/cve/CVE-2026-105238
- https://vuldb.com/submit/975707
- https://vuldb.com/vuln/413450
- https://vuldb.com/vuln/413450/cti
- https://github.com/advisories/GHSA-rhg8-4whm-xj7w