NextChat是一个用于快速部署私人 ChatGPT 网页应用的项目。 NextChat 2.11.2及之前版本存在安全漏洞,该漏洞源于存在服务器请求伪造(SSRF)和跨站脚本(XSS)漏洞。攻击者可利用该漏洞对内部HTTP端点进行读取访问等操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ChatGPTNextWeb | NextChat | 0 ~ 2.11.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Full-Read SSRF/XSS in NextChat, aka ChatGPT-Next-Web | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-49785.yaml | POC Details |
| 2 | None | https://github.com/hyunnna/NextChat_SSRF_CVE-2023-49785 | POC Details |
No comments yet