{"data":{"id":"d819d5b5-fbf4-46f4-9ee9-a2a128cc06bd","title":"CVE-2026-105238: A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of…","summary":"A flaw in ChatGPTNextWeb NextChat up to version 2.16.1 affects the proxyHandler function in app/api/proxy.ts, within the Proxy Fallback Handler component. Manipulating the x-base-url argument causes server-side request forgery, and the attack can be launched remotely. A public exploit has been published, and a pull request to fix the issue is awaiting acceptance.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105238","publishedAt":"2026-10-05T07:16:30.180Z","cveId":"CVE-2026-105238","cweIds":["CWE-918"],"cvssScore":"7.3","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["NextChat","ChatGPTNextWeb NextChat"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00392,"epssCheckedAt":"2026-10-10T02:57:39.298Z","kevDateAdded":null,"advisoryAliases":["GHSA-rhg8-4whm-xj7w"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:42:59.067Z","patchAvailable":null,"disclosureDate":"2026-10-05T07:16:30.180Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}