Impact
The flaw lies in the chat-server component of songxinjianqwe Chat, where an attacker can craft requests that cause the server to reach arbitrary URLs. This server‑side request forgery can be triggered remotely and may expose internal network resources, sensitive data, or enable further attacks. The weakness is classified as CWE‑918 and is considered a high‑severity vulnerability with a CVSS score of 6.9.
Affected Systems
The affected product is songxinjianqwe Chat, specifically the chat-server module up to commit ac63d25297079eed5e4ba7e88d3b7a032637150d. The product follows a rolling release model, so specific affected versions are not listed but any release before the mentioned commit is potentially vulnerable.
Risk and Exploitability
A publicly available exploit is known, and the attack can be initiated from a remote location. The CVSS score of 6.9 indicates moderate to high risk, while the lack of EPSS data suggests uncertainty about current exploitation frequency. The vulnerability is not listed in the CISA KEV catalog, but the remote nature of the attack and SSRF potential necessitate immediate action.
OpenCVE Enrichment