Nextchat is a messaging and collaboration platform whose vulnerability profile centers on web-application input-handling and access-control issues, including server-side request forgery, path traversal, and cross-site scripting. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nextchat over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-49785CRITICAL NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and | Mar 12, 2024 | 9.8 | 84 | NO | YES |
CVE-2026-7177HIGH A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. | Apr 27, 2026 | 7.3 | 28 | NO | NO |
CVE-2026-7178HIGH A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoin | Apr 27, 2026 | 7.3 | 27 | NO | NO |
CVE-2025-50735HIGH Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing attackers to | Nov 3, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nextchat.
Media articles that mention a CVE ID that affects a product developed by Nextchat — matched by CVE ID, not by vendor name.