Impact
A flaw in the proxyHandler function of ChatGPTNextWeb's NextChat component allows an attacker to manipulate the x-base-url header. This causes the server to make HTTP requests to arbitrary URLs specified in the header, enabling a server‑side request forgery attack. An attacker can use this to access internal resources, exfiltrate data, or pivot to additional systems. The vulnerability applies to all releases up to 2.16.1 and can be triggered remotely through normal HTTP traffic.
Affected Systems
All deployments of the ChatGPTNextWeb NextChat product with versions 2.16.1 or earlier. The vulnerability resides in the Proxy Fallback Handler implemented in app/api/proxy.ts.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. No EPSS information is available and the flaw is not listed in the CISA KEV catalog, but an exploit has been published and can be executed remotely. The attack vector likely involves sending a crafted request to the /api/proxy endpoint with a malicious x-base-url header, forcing the server to reach arbitrary endpoints, potentially exposing internal services or sensitive data.
OpenCVE Enrichment