Skip to content
Threat Feed
high advisory

SSRF Vulnerability in ChatGPTNextWeb NextChat

A server-side request forgery vulnerability in ChatGPTNextWeb NextChat up to version 2.16.1 allows remote attackers to manipulate the x-base-url header to perform unauthorized requests from the application server.

CVE search metadata

CVE search record: CVE-2026-105238. Severity: high. CVSS: 7.3. KEV: no. Product: NextChat (<= 2.16.1). Brief: SSRF Vulnerability in ChatGPTNextWeb NextChat. Brief link: https://feed.craftedsignal.io/briefs/2026-10-nextchat-ssrf/

ChatGPTNextWeb NextChat versions up to and including 2.16.1 contain a server-side request forgery (SSRF) vulnerability. The flaw exists within the proxyHandler function located in app/api/proxy.ts, specifically within the component responsible for proxy fallback handling. By manipulating the 'x-base-url' HTTP header, an unauthenticated remote attacker can force the application server to make arbitrary requests to internal or external resources. This can potentially expose sensitive internal services, metadata endpoints, or infrastructure otherwise protected by network boundaries. While a fix has been proposed via pull request, it remains pending acceptance at the time of reporting. Organizations utilizing NextChat should monitor for suspicious outbound traffic patterns originating from the server hosting the application until an official patch is verified and deployed.

Impact

Successful exploitation of this SSRF vulnerability permits unauthorized interaction with resources reachable by the application server. This could lead to information disclosure, unauthorized access to internal management interfaces, or service disruption. As the vulnerability is remotely exploitable without authentication, it poses a significant risk to the integrity of internal network segments hosting the application.

Recommendation

  • Monitor HTTP traffic for unexpected requests originating from the NextChat application server to sensitive internal IP ranges or cloud metadata services (e.g., 169.254.169.254).
  • Restrict the application server's outbound network access to only necessary external endpoints via egress firewall rules.
  • Review the pending security patches provided by the project maintainers and update to a remediated version once finalized and released.

Immediate actions

Restrict egress traffic from the application server to non-essential internal and external destinations

IT Operations 24h

Threat Hunt

Analyze web server logs for HTTP requests containing x-base-url headers with internal IP addresses

T1190 medium medium confidence hunt now

Data: webserver_logs

Mitigations

Upgrade NextChat to the patched version once released

immediate IT Operations

CVE-2026-105238