Executive brief
NextChat is a cross-platform chat interface for interacting with AI models like ChatGPT. The application contains an SSRF (server-side request forgery) vulnerability in its /api/cors endpoint that allows attackers to read and modify internal resources, potentially exposing sensitive data or enabling lateral movement within a network. Attackers can also forge requests to external targets, masking their source IP.
Technical details
NextChat versions 2.11.2 and earlier contain a server-side request forgery (SSRF) and cross-site scripting (XSS) vulnerability in the /api/cors endpoint (CWE-918, CWE-79). The vulnerable endpoint fails to properly validate or restrict HTTP requests, allowing unauthenticated attackers to send arbitrary requests via GET, POST, PUT, and other HTTP methods to internal endpoints or external targets. This enables attackers to read internal HTTP resources, modify data via POST/PUT requests, and use the application as an open proxy to mask their source IP. No authentication or user interaction is required to exploit this vulnerability. As of the advisory publication, no patch has been released; mitigation involves network isolation or not exposing the application to the public internet.
Affected products
- ChatGPT-Next-Web NextChat 2.11.2 and prior
Timeline
- 2024-08-05: disclosed: Advisory published by GitHub Security Advisory Database
- 2024-03-12: other: CVE-2023-49785 published on NVD