


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the compone…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 23:01:40
Source:
nvd.nist.gov
Web Technologies
A server-side request forgery (SSRF) vulnerability has been identified in ChatGPTNextWeb NextChat up to version 2.16.1. The vulnerability affects the storeUrl function in the app/api/artifacts/route.ts file of the Artifacts Endpoint component. The issue can be exploited remotely by manipulating the argument ID parameter. A public exploit is available, increasing the risk of active exploitation. The project maintainers have been notified through an issue report but have not yet responded to the vulnerability disclosure.
Technical details
Mitigation steps:
Affected products:
ChatGPTNextWeb NextChat
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7178
https://gist.github.com/YLChen-007/43252d45d75e8bdd2d45136fd6ffe8a5
https://github.com/ChatGPTNextWeb/NextChat/
https://github.com/ChatGPTNextWeb/NextChat/issues/6741
https://vuldb.com/submit/797646
https://vuldb.com/vuln/359780
https://vuldb.com/vuln/359780/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
