High severity7.3NVD Advisory· Published Apr 27, 2026· Updated Apr 30, 2026
CVE-2026-7177
CVE-2026-7177
Description
A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- gist.github.com/YLChen-007/da6b00024f5b7e1d4fa0658c19b77fbfnvdExploitThird Party Advisory
- vuldb.com/submit/797645nvdExploitThird Party Advisory
- vuldb.com/vuln/359779nvdThird Party AdvisoryVDB Entry
- github.com/ChatGPTNextWeb/NextChat/issues/6742nvdIssue Tracking
- vuldb.com/vuln/359779/ctinvdPermissions Required
News mentions
0No linked articles in our index yet.