QID 731244
Date Published: 2024-03-13
QID 731244: NextChat Server-Side Request Forgery/Cross-site scripting (SSRF/XSS) Vulnerability (CVE-2023-49785)
NextChat, also known as ChatGPT-Next-Web, stands out as the most extensively utilized standalone Generation AI chatbot. It is hosted on GitHub, boasting over 63,000 stars and 52,000 forks. SSRF vulnerabilities exhibit a wide range of real-world impacts, and this specific SSRF vulnerability ranks among the most severe.
Advisory/Patched version has not been released by vendor yet.
QID Detection Logic (Unauthenticated):
This unauthenticated QID verifies the following endpoints:
- /api/cors/
Successful exploitation of the vulnerability may allow a remote attacker to disclose sensitive information on affected installations of NextChat.
Solution
N/A
Vendor References
CVEs related to QID 731244
Software Advisories
| Advisory ID | Software | Component | Link |
|---|