PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7223 BigSweetPotatoStudio CVE debrief

A server-side request forgery vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. The issue affects the AI Proxy Middleware's fetch function in the file packages/core/src/http/aiProxyMiddleware.mts. Manipulation of the baseurl argument can lead to server-side request forgery. The vulnerability can be exploited remotely, and a public exploit is available. The project was informed but has not yet responded.

Vendor
BigSweetPotatoStudio
Product
HyperChat
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-28
Original CVE updated
2026-07-24
Advisory published
2026-04-28
Advisory updated
2026-07-24

Who should care

Users of BigSweetPotatoStudio HyperChat up to version 2.0.0-alpha.63 should be aware of this vulnerability and take necessary precautions to protect their systems, especially those operating in environments where AI Proxy Middleware is exposed to untrusted input. This includes reviewing system configurations, ensuring proper security controls are in place, and preparing for potential updates or patches from the vendor.

Technical summary

The vulnerability is located in the AI Proxy Middleware's fetch function within the file packages/core/src/http/aiProxyMiddleware.mts of BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. The issue arises from improper handling of the baseurl argument, allowing for server-side request forgery attacks. This vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. Successful exploitation could allow attackers to manipulate server-side requests, potentially leading to unauthorized access or data breaches. The vulnerability can be exploited remotely, and a public exploit is available.

Defensive priority

Medium priority should be given to patching or mitigating this vulnerability, as it can be exploited remotely and a public exploit is available.

Recommended defensive actions

  • Inventory and check systems using BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63 for exposure.
  • Apply patches or updates if available from the vendor.
  • Implement compensating controls such as monitoring and exception tracking.
  • Consider disabling or restricting access to the affected AI Proxy Middleware if patches are not available.
  • Review system configurations for potential vulnerabilities in AI Proxy Middleware.
  • Monitor for suspicious activity that could indicate exploitation attempts.
  • Develop and implement a remediation plan for exposed systems.

Evidence notes

The CVE record was published on 2026-04-28T04:16:29.043Z and last modified on 2026-07-24T08:10:00.150Z. The NVD entry is currently Deferred. The vulnerability has been publicly disclosed, and a public exploit is available. However, the project has not yet responded to the issue report.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-7223 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-7223

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-7223 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7223

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.