HighVulnerability
CVE-2026-105238: A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This vulnerability affects the function proxyHandler of…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105238
- Published
- Record updated
Summary
A flaw in ChatGPTNextWeb NextChat up to version 2.16.1 affects the proxyHandler function in app/api/proxy.ts, within the Proxy Fallback Handler component. Manipulating the x-base-url argument causes server-side request forgery, and the attack can be launched remotely. A public exploit has been published, and a pull request to fix the issue is awaiting acceptance.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database