CVE-2026-7178: A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulat...
Added to the CISA Known Exploited Vulnerabilities catalog on 27 Apr 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 7.3.
A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulation of the argument ID causes server-side request forgery. It is possible to initiate the attack rem...
Required action: Review and patch if applicable to your AI infrastructure.