CPE
A server-side request forgery vulnerability in ChatGPTNextWeb NextChat up to version 2.16.1 allows remote attackers to manipulate the x-base-url header to perform unauthorized requests from the application server.