CVE-2026-105238: 
NextChat Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-105238 is a Server-Side Request Forgery (SSRF) vulnerability in ChatGPTNextWeb NextChat affecting versions up to and including 2.16.1. The flaw resides in the proxyHandler function within app/api/proxy.ts, where the x-base-url request header is used without validation to construct upstream HTTP requests. The vulnerability was first reported on June 2, 2026, publicly disclosed via GitHub issue on July 5, 2026, and formally published to the NVD and GitHub Advisory Database on October 5, 2026. It carries a CVSS v3.1 base score of 7.3 (High) and a CVSS v4.0 base score of 5.5 (Medium) (GitHub Advisory, Feedly).

Détails techniques

The root cause is CWE-918 (Server-Side Request Forgery): the proxyHandler in app/api/proxy.ts reads the attacker-controlled x-base-url header and directly interpolates it into a server-side fetch() call without any authentication check, URL allowlist, or input sanitization (GitHub Issue). The Next.js catch-all route app/api/[provider]/[...path]/route.ts dispatches unrecognized provider names to proxyHandler as a fallback — meaning any request to /api/<arbitrary-provider>/<path> triggers the vulnerable code path. Unlike the named provider handlers (OpenAI, Anthropic, Google), proxyHandler never calls auth(), so the CODE access-control environment variable provides no protection. Additionally, next.config.mjs sets Access-Control-Allow-Origin: * and Access-Control-Allow-Headers: *, making the endpoint reachable cross-origin from any web page and enabling drive-by exploitation (GitHub Issue, GitHub PR).

Impact

An unauthenticated remote attacker can force the NextChat server to make arbitrary HTTP requests to any internal or external endpoint, including cloud metadata services (e.g., http://169.254.169.254 for AWS IAM credentials), internal databases, Redis instances, container sidecars, and other services on the server's network segment (GitHub Issue). Response bodies from internal services are relayed back to the attacker, enabling data exfiltration. The vulnerability also enables API key leakage: a related flaw (referenced in PR #6884) allows the server's OPENAI_API_KEY to be exfiltrated via a crafted x-base-url value that passes an incomplete hostname substring check (GitHub PR). All self-hosted NextChat deployments are affected regardless of whether the CODE environment variable is configured.

Exploitabilité

A proof-of-concept exploit was publicly disclosed alongside the GitHub issue report, demonstrating unauthenticated SSRF to arbitrary HTTP listeners and the AWS instance metadata endpoint (GitHub Issue). The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. No evidence of in-the-wild exploitation has been observed at the time of publication, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is 0.0, reflecting low observed exploitation probability at this time (GitHub Advisory, Feedly). No threat actor attribution has been reported.

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing NextChat instances (versions ≤ 2.16.1) using search engines like Shodan or Censys, looking for the Docker image yidadaa/chatgpt-next-web or the NextChat web UI on port 3000.
  2. Identify the vulnerable endpoint: Any request to /api/<non-existent-provider>/<path> will fall through to the proxyHandler fallback. Choose an arbitrary provider name not matching known values (e.g., anyprovider).
  3. Craft the SSRF request: Send an unauthenticated HTTP GET request with the x-base-url header set to the target internal URL:
    GET /api/anyprovider/anypath HTTP/1.1
    Host: <nextchat-host>:3000
    x-base-url: http://<internal-target>
  4. Target cloud metadata: To retrieve AWS IAM credentials, set x-base-url: http://169.254.169.254 and path to latest/meta-data/iam/security-credentials/:
    GET /api/anyprov/latest/meta-data/iam/security-credentials/ HTTP/1.1
    Host: <nextchat-host>:3000
    x-base-url: http://169.254.169.254
  5. Receive exfiltrated data: The NextChat server performs the server-side fetch and returns the response body (e.g., IAM credential JSON, internal service data) directly to the attacker.
  6. Enumerate internal network: Iterate over internal IP ranges and ports via the x-base-url header to map internal services, databases, or APIs accessible from the NextChat server's network (GitHub Issue).

Indicateurs de compromis

  • Network: Outbound HTTP requests from the NextChat server process to RFC1918 addresses (10.x.x.x, 172.16-31.x.x, 192.168.x.x), link-local addresses (169.254.x.x), or unexpected external hosts; unusual connections to port 80/443 on internal infrastructure originating from the NextChat container.
  • Logs: Web server access logs showing requests to /api/<unknown-provider>/ paths with an x-base-url header present; Next.js server logs showing fetch calls to internal or metadata endpoints; HTTP 200 responses to requests with non-standard provider names in the URL path.
  • Application Behavior: Responses to /api/<arbitrary-provider>/ requests containing internal service banners, JSON metadata, or cloud credential structures (e.g., AWS AccessKeyId, SecretAccessKey, Token fields).
  • Process: The Node.js process running NextChat initiating unexpected outbound TCP connections to internal network segments or cloud metadata IPs (GitHub Issue, GitHub PR).

Atténuation et solutions de contournement

The recommended remediation is to upgrade NextChat to a version newer than 2.16.1 once a patched release is available; as of the disclosure date, a fix pull request (PR #6884) has been submitted but awaits maintainer acceptance (GitHub PR). The proposed fix rejects non-HTTP(S) x-base-url values and blocks requests to private/RFC1918, CGNAT, link-local, loopback, and cloud metadata addresses (e.g., 169.254.169.254, metadata.google.internal) with HTTP 400, and restricts OPENAI_API_KEY injection to requests targeting exactly api.openai.com. As interim workarounds: implement network-level egress controls to block the NextChat server from reaching internal network ranges and metadata endpoints; deploy a reverse proxy or WAF rule to reject requests containing an x-base-url header; and restrict public exposure of the NextChat instance where possible (GitHub Advisory, Feedly).

Réactions de la communauté

The vulnerability was originally reported privately via GitHub Security Advisories (GHSA-2wvx-vcmx-h8fr) on June 2, 2026, with no response from maintainers, prompting the reporter (geo-chen) to file a public issue on July 5, 2026 (GitHub Issue). A community contributor (BetterAndBetterII) submitted PR #6884 on August 28, 2026 with a comprehensive fix, but it remained unmerged as of the CVE publication date (GitHub PR). The slow maintainer response to a critical unauthenticated SSRF in a widely-deployed AI chat application (88.8k GitHub stars, 58.9k forks) drew attention from the security community.

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté NextChat Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-82639HIGH8.7
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonAug 30, 2026
CVE-2026-105238MEDIUM5.5
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonOct 05, 2026
CVE-2026-7644MEDIUM5.5
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonMay 02, 2026
CVE-2026-7178MEDIUM5.5
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonApr 27, 2026
CVE-2026-7643LOW2.1
  • NextChat logoNextChat
  • cpe:2.3:a:nextchat:nextchat
NonNonMay 02, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités