top of page
perceptive_background_267k.jpg

A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the compone…

Published:

26 April 2026 at 22:00:00

Alert date:

27 April 2026 at 23:01:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

A server-side request forgery (SSRF) vulnerability has been identified in ChatGPTNextWeb NextChat up to version 2.16.1. The vulnerability affects the storeUrl function in the app/api/artifacts/route.ts file of the Artifacts Endpoint component. The issue can be exploited remotely by manipulating the argument ID parameter. A public exploit is available, increasing the risk of active exploitation. The project maintainers have been notified through an issue report but have not yet responded to the vulnerability disclosure.

Technical details

Mitigation steps:

Affected products:

ChatGPTNextWeb NextChat

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page