NextChat < 2.11.3 Server-Side Request Forgery
Discription

NextChat (formerly ChatGPT-Next-Web) versions prior to 2.11.3 are vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting attacks, allowing remote and unauthenticated attacker to make the vulnerable instance issue arbitrary requests on both external or internal assets through the '/api/cors' endpoint or to execute JavaScript in the application users browsers…Read More

Back to Main

Subscribe for the latest news: