PatchSiren

BigSweetPotatoStudio CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM BigSweetPotatoStudio CVE published 2026-04-28

CVE-2026-7223

A server-side request forgery vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. The issue affects the AI Proxy Middleware's fetch function in the file packages/core/src/http/aiProxyMiddleware.mts. Manipulation of the baseurl argument can lead to server-side request forgery. The vulnerability can be exploited remotely, and a public exploit is available. The project was in [truncated]