CVE-2026-7177: A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. The manipulation ...

Added to the CISA Known Exploited Vulnerabilities catalog on 27 Apr 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 7.3.

A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has bee...

Required action: Review and patch if applicable to your AI infrastructure.