{"id":"CVE-2026-105238","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-105238","summary":"A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler.…","details":"A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of the file app/api/proxy.ts of the component Proxy Fallback Handler. This manipulation of the argument x-base-url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.","published":"2026-10-05T07:16:30.180","modified":"2026-10-05T07:16:30.180","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/ChatGPTNextWeb/NextChat/pull/6884","label":"ChatGPTNextWeb/NextChat#6884"},"references":[{"type":"WEB","url":"https://github.com/ChatGPTNextWeb/NextChat/"},{"type":"WEB","url":"https://github.com/ChatGPTNextWeb/NextChat/issues/6813"},{"type":"WEB","url":"https://github.com/ChatGPTNextWeb/NextChat/pull/6884"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-105238"},{"type":"WEB","url":"https://vuldb.com/submit/975707"},{"type":"WEB","url":"https://vuldb.com/vuln/413450"},{"type":"WEB","url":"https://vuldb.com/vuln/413450/cti"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-05T07:16:30.180"}}