CVE-2026-105238
Received Received - Intake

Server-Side Request Forgery in NextChat Proxy Handler

Vulnerability report for CVE-2026-105238, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
chatgptnextweb nextchat to 2.16.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in NextChat up to version 2.16.1. It exists in the proxy fallback handler of app/api/proxy.ts where the x-base-url header is used to make HTTP requests without proper validation. Attackers can manipulate this header to force the server to make requests to arbitrary internal or external URLs, potentially accessing sensitive services or data.

Detection Guidance

To detect this SSRF vulnerability in NextChat, monitor network traffic for requests containing the x-base-url header. Check logs for HTTP 400 errors indicating blocked requests to private/metadata/loopback targets. Inspect proxy handler logs in app/api/proxy.ts for unusual outbound requests to non-http(s) URLs or internal IPs.

Impact Analysis

This SSRF flaw allows unauthenticated attackers to probe internal network services, cloud metadata endpoints (AWS, GCP, Azure), and adjacent hosts. It can lead to data exfiltration, theft of IAM credentials, or bypassing access controls. The vulnerability is accessible from any web page due to permissive CORS headers, enabling drive-by exploitation.

Compliance Impact

This vulnerability, an unauthenticated Server-Side Request Forgery (SSRF), could lead to unauthorized access to internal systems, data exfiltration, or credential theft. For GDPR, this may result in unauthorized processing of personal data or breaches requiring notification under Articles 33-34. Under HIPAA, it could expose protected health information (PHI) if internal systems are accessed, triggering breach notification requirements.

Mitigation Strategies

Apply the pending pull request fix which enforces strict hostname matching for api.openai.com, rejects non-http(s) URLs, and blocks private/metadata/loopback targets. Disable the proxy fallback route if unused. Update to the latest patched version once available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105238. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart