PatchSiren

ChatGPTNextWeb CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ChatGPTNextWeb CVE published 2026-08-30

CVE-2026-82639

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T14:17:03.750Z and has not been modified since then. The vulnerability affects NextChat versions from 2.15.8 through 2.16.1, allowing attackers to obtain the server's OpenAI API key due to improper URL validation in the proxy endpoint. The x-base-url header is validated using substring matching in [truncated]

MEDIUM ChatGPTNextWeb CVE published 2026-04-27

CVE-2026-7178

A server-side request forgery vulnerability has been identified in ChatGPTNextWeb NextChat up to 2.16.1. The vulnerability affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulation of the argument ID causes server-side request forgery. It is possible to initiate the attack remotely. The project was informed of the problem early through an i [truncated]