Vulnerabilidad · Publicado 05/10/2026
Se ha identificado una vulnerabilidad de Server-Side Request Forgery (SSRF) en ChatGPTNextWeb NextChat versiones hasta 2.16.1, ubicada en la función proxyHandler del componente Proxy Fallback Handler (app/api/proxy.ts). Un atacante remoto puede manipular el argumento x-base-url para ejecutar solicitudes HTTP arbitrarias desde el servidor afectado, potencialmente comprometiendo datos internos, accediendo a servicios de red privados o saltando controles de seguridad perimetral. La explotación es remota y código de prueba ya está disponible públicamente.
A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-918
Publicado en NIST NVD.