Description
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Server-side request forgery
Action: Immediate Patch
AI Analysis

Impact

A flaw in the proxyHandler function of ChatGPTNextWeb's NextChat component allows an attacker to manipulate the x-base-url header. This causes the server to make HTTP requests to arbitrary URLs specified in the header, enabling a server‑side request forgery attack. An attacker can use this to access internal resources, exfiltrate data, or pivot to additional systems. The vulnerability applies to all releases up to 2.16.1 and can be triggered remotely through normal HTTP traffic.

Affected Systems

All deployments of the ChatGPTNextWeb NextChat product with versions 2.16.1 or earlier. The vulnerability resides in the Proxy Fallback Handler implemented in app/api/proxy.ts.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. No EPSS information is available and the flaw is not listed in the CISA KEV catalog, but an exploit has been published and can be executed remotely. The attack vector likely involves sending a crafted request to the /api/proxy endpoint with a malicious x-base-url header, forcing the server to reach arbitrary endpoints, potentially exposing internal services or sensitive data.

Generated by OpenCVE AI on October 5, 2026 at 08:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade NextChat to a patched version once the pull request is merged and the CVE is fixed.
  • As a temporary workaround, remove or disable the /api/proxy endpoint or the Proxy Fallback component to eliminate the vulnerable entry point until a patch is available.
  • Configure outbound network access for the NextChat server to allow only whitelisted destinations, preventing the server from contacting internal or sensitive resources via the x-base-url header.

Generated by OpenCVE AI on October 5, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Title ChatGPTNextWeb NextChat Proxy Fallback proxy.ts proxyHandler server-side request forgery
First Time appeared Nextchat
Nextchat nextchat
Weaknesses CWE-918
CPEs cpe:2.3:a:nextchat:nextchat:*:*:*:*:*:*:*:*
Vendors & Products Nextchat
Nextchat nextchat
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Nextchat Nextchat
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T06:15:11.244Z

Reserved: 2026-10-04T16:15:43.837Z

Link: CVE-2026-105238

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T07:16:30.180

Modified: 2026-10-05T07:16:30.180

Link: CVE-2026-105238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T08:30:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)