
PEACH
Un cadre d’isolation des locataires
CVE-2026-105238 is a Server-Side Request Forgery (SSRF) vulnerability in ChatGPTNextWeb NextChat affecting versions up to and including 2.16.1. The flaw resides in the proxyHandler function within app/api/proxy.ts, where the x-base-url request header is used without validation to construct upstream HTTP requests. The vulnerability was first reported on June 2, 2026, publicly disclosed via GitHub issue on July 5, 2026, and formally published to the NVD and GitHub Advisory Database on October 5, 2026. It carries a CVSS v3.1 base score of 7.3 (High) and a CVSS v4.0 base score of 5.5 (Medium) (GitHub Advisory, Feedly).
The root cause is CWE-918 (Server-Side Request Forgery): the proxyHandler in app/api/proxy.ts reads the attacker-controlled x-base-url header and directly interpolates it into a server-side fetch() call without any authentication check, URL allowlist, or input sanitization (GitHub Issue). The Next.js catch-all route app/api/[provider]/[...path]/route.ts dispatches unrecognized provider names to proxyHandler as a fallback — meaning any request to /api/<arbitrary-provider>/<path> triggers the vulnerable code path. Unlike the named provider handlers (OpenAI, Anthropic, Google), proxyHandler never calls auth(), so the CODE access-control environment variable provides no protection. Additionally, next.config.mjs sets Access-Control-Allow-Origin: * and Access-Control-Allow-Headers: *, making the endpoint reachable cross-origin from any web page and enabling drive-by exploitation (GitHub Issue, GitHub PR).
An unauthenticated remote attacker can force the NextChat server to make arbitrary HTTP requests to any internal or external endpoint, including cloud metadata services (e.g., http://169.254.169.254 for AWS IAM credentials), internal databases, Redis instances, container sidecars, and other services on the server's network segment (GitHub Issue). Response bodies from internal services are relayed back to the attacker, enabling data exfiltration. The vulnerability also enables API key leakage: a related flaw (referenced in PR #6884) allows the server's OPENAI_API_KEY to be exfiltrated via a crafted x-base-url value that passes an incomplete hostname substring check (GitHub PR). All self-hosted NextChat deployments are affected regardless of whether the CODE environment variable is configured.
A proof-of-concept exploit was publicly disclosed alongside the GitHub issue report, demonstrating unauthenticated SSRF to arbitrary HTTP listeners and the AWS instance metadata endpoint (GitHub Issue). The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. No evidence of in-the-wild exploitation has been observed at the time of publication, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is 0.0, reflecting low observed exploitation probability at this time (GitHub Advisory, Feedly). No threat actor attribution has been reported.
yidadaa/chatgpt-next-web or the NextChat web UI on port 3000./api/<non-existent-provider>/<path> will fall through to the proxyHandler fallback. Choose an arbitrary provider name not matching known values (e.g., anyprovider).x-base-url header set to the target internal URL:GET /api/anyprovider/anypath HTTP/1.1
Host: <nextchat-host>:3000
x-base-url: http://<internal-target>x-base-url: http://169.254.169.254 and path to latest/meta-data/iam/security-credentials/:GET /api/anyprov/latest/meta-data/iam/security-credentials/ HTTP/1.1
Host: <nextchat-host>:3000
x-base-url: http://169.254.169.254x-base-url header to map internal services, databases, or APIs accessible from the NextChat server's network (GitHub Issue)./api/<unknown-provider>/ paths with an x-base-url header present; Next.js server logs showing fetch calls to internal or metadata endpoints; HTTP 200 responses to requests with non-standard provider names in the URL path./api/<arbitrary-provider>/ requests containing internal service banners, JSON metadata, or cloud credential structures (e.g., AWS AccessKeyId, SecretAccessKey, Token fields).The recommended remediation is to upgrade NextChat to a version newer than 2.16.1 once a patched release is available; as of the disclosure date, a fix pull request (PR #6884) has been submitted but awaits maintainer acceptance (GitHub PR). The proposed fix rejects non-HTTP(S) x-base-url values and blocks requests to private/RFC1918, CGNAT, link-local, loopback, and cloud metadata addresses (e.g., 169.254.169.254, metadata.google.internal) with HTTP 400, and restricts OPENAI_API_KEY injection to requests targeting exactly api.openai.com. As interim workarounds: implement network-level egress controls to block the NextChat server from reaching internal network ranges and metadata endpoints; deploy a reverse proxy or WAF rule to reject requests containing an x-base-url header; and restrict public exposure of the NextChat instance where possible (GitHub Advisory, Feedly).
The vulnerability was originally reported privately via GitHub Security Advisories (GHSA-2wvx-vcmx-h8fr) on June 2, 2026, with no response from maintainers, prompting the reporter (geo-chen) to file a public issue on July 5, 2026 (GitHub Issue). A community contributor (BetterAndBetterII) submitted PR #6884 on August 28, 2026 with a comprehensive fix, but it remained unmerged as of the CVE publication date (GitHub PR). The slow maintainer response to a critical unauthenticated SSRF in a widely-deployed AI chat application (88.8k GitHub stars, 58.9k forks) drew attention from the security community.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."