PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7178 ChatGPTNextWeb CVE debrief

A server-side request forgery vulnerability has been identified in ChatGPTNextWeb NextChat up to 2.16.1. The vulnerability affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulation of the argument ID causes server-side request forgery. It is possible to initiate the attack remotely. The project was informed of the problem early through an issue report but has not responded yet. Administrators and users should be aware of the vulnerability and take necessary precautions.

Vendor
ChatGPTNextWeb
Product
NextChat
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-27
Original CVE updated
2026-07-24
Advisory published
2026-04-27
Advisory updated
2026-07-24

Who should care

Administrators and users of ChatGPTNextWeb NextChat up to 2.16.1 should be aware of this vulnerability and take necessary precautions to defend against potential attacks. This includes reviewing and restricting access to the Artifacts Endpoint component, implementing compensating controls such as monitoring and exception tracking, and applying patches or updates if available.

Technical summary

The vulnerability is caused by a weakness in the storeUrl function of the app/api/artifacts/route.ts file in the Artifacts Endpoint component of ChatGPTNextWeb NextChat up to 2.16.1. An attacker can manipulate the argument ID to cause server-side request forgery. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet. Administrators and users should review system logs for potential attacks and monitor for suspicious activity. The exploit has been made public and could be used for attacks, emphasizing the need for prompt mitigation.

Defensive priority

Medium priority should be given to patching or mitigating this vulnerability, as it has been made public and could be used for attacks.

Recommended defensive actions

  • Inventory and check affected ChatGPTNextWeb NextChat versions up to 2.16.1
  • Apply patches or updates if available
  • Implement compensating controls such as monitoring and exception tracking
  • Review and restrict access to the Artifacts Endpoint component
  • Monitor for suspicious activity
  • Review system logs for potential attacks
  • Perform a thorough risk assessment

Evidence notes

The CVE record was published on 2026-04-27T22:16:19.050Z and was last modified on 2026-07-24T08:10:00.150Z. The NVD entry is currently Analyzed. The vulnerability has been made public and could be used for attacks. There is no information on whether the project has responded to the issue report yet. The weakness affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint in ChatGPTNextWeb NextChat up to 2.16.1.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-27T22:16:19.050Z and has not been modified since then. The NVD entry is currently Analyzed.