MEDIUM
BigSweetPotatoStudio
CVE published 2026-04-28
CVE-2026-7223
A server-side request forgery vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. The issue affects the AI Proxy Middleware's fetch function in the file packages/core/src/http/aiProxyMiddleware.mts. Manipulation of the baseurl argument can lead to server-side request forgery. The vulnerability can be exploited remotely, and a public exploit is available. The project was in [truncated]