MEDIUM
ChatGPTNextWeb
CVE published 2026-04-27
CVE-2026-7178
A server-side request forgery vulnerability has been identified in ChatGPTNextWeb NextChat up to 2.16.1. The vulnerability affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulation of the argument ID causes server-side request forgery. It is possible to initiate the attack remotely. The project was informed of the problem early through an i [truncated]