Sceawere
Vulnerability Detail
CVE-2026-105238UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
NextChat Server-Side Request Forgery
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 11h ago
- Vendor
- ChatGPTNextWeb
- Product
- NextChat
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T07:16:30.180Z",
"pubdate": "2026-10-05T07:16:30.180Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in ChatGPTNextWeb NextChat up to version 2.16.1.\nThe flaw originates from improper validation of user-supplied input within the proxy handling logic, specifically via the x-base-url header.\nThis vulnerability allows an unauthenticated remote attacker to coerce the server into making arbitrary HTTP requests to internal or external resources.\nSuccessful exploitation may lead to unauthorized access to internal services, sensitive data exfiltration, or interactions with internal network infrastructure not intended to be exposed.\nThe risk level is high, as the attack can be initiated remotely without prior authentication, and public exploit code is currently available.",
"technicalDetails": "The vulnerability resides in the proxyHandler function located in app/api/proxy.ts, which is responsible for the component Proxy Fallback Handler.\nThe root cause of this SSRF vulnerability is the lack of strict allowlisting or sanitization of the x-base-url request header.\nWhen a request is processed by proxyHandler, the application extracts the value provided in the x-base-url header and uses it to construct the destination URL for an outbound proxy request.\nBecause the application does not validate that the destination domain or IP address is trustworthy, an attacker can manipulate this header to point to arbitrary targets.\nAttack flow: An attacker crafts an HTTP request containing a malicious x-base-url parameter, targeting either an external attacker-controlled server or an internal resource (e.g., localhost, internal APIs, metadata services).\nUpon receiving the request, the proxyHandler function utilizes the untrusted input to initiate a server-side request.\nThe server acts as a proxy, forwarding the attacker's request to the specified target. This bypasses client-side firewalls and security controls, as the request originates from the trusted server environment.\nThe impact includes the ability to scan internal network segments, perform port scanning on local services, and interact with internal interfaces that lack robust authentication.\nThis vulnerability is classified as remote and unauthenticated, meaning any user capable of reaching the API endpoint can exploit the flaw.\nThe availability of published exploit code exacerbates the risk, lowering the barrier to entry for potential threat actors."
}