CVE-2026-105238 | ChatGPTNextWeb NextChat up to 2.16.1 Proxy Fallback app/api/proxy.ts proxyHandler x-base-url server-side request forgery (Issue 6813)
A vulnerability, which was classified as critical, has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery.
The identification of this vulnerability is CVE-2026-105238. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More