NextChat has full-read SSRF and XSS vulnerability in /api/cors endpoint
        
  Critical severity
        
          GitHub Reviewed
      
        Published
          Aug 5, 2024 
          to the GitHub Advisory Database
          •
          Updated Aug 5, 2024 
      
  
Description
        Published by the National Vulnerability Database
      Mar 12, 2024 
    
  
        Published to the GitHub Advisory Database
      Aug 5, 2024 
    
  
        Reviewed
      Aug 5, 2024 
    
  
        Last updated
      Aug 5, 2024 
    
  
NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also write access using HTTP POST, PUT, and other methods. Attackers can also use this vulnerability to mask their source IP by forwarding malicious traffic intended for other Internet targets through these open proxies. As of time of publication, no patch is available, but other mitigation strategies are available. Users may avoid exposing the application to the public internet or, if exposing the application to the internet, ensure it is an isolated network with no access to any other internal resources.
References