CVE-2026-7223
7.3BigSweetPotatoStudio · HyperChat
A Server-Side Request Forgery (SSRF) vulnerability exists in the AI Proxy Middleware of BigSweetPotatoStudio HyperChat, allowing remote, unauthenticated attackers to trigger arbitrary outbound requests.
Executive summary
An unauthenticated Server-Side Request Forgery vulnerability in BigSweetPotatoStudio HyperChat allows remote attackers to force the server to make unauthorized outbound network requests.
Vulnerability
The vulnerability exists in the AI Proxy Middleware, specifically within the fetch function of packages/core/src/http/aiProxyMiddleware.mts. The application fails to validate the baseurl request header, allowing an unauthenticated attacker to manipulate this input to coerce the server into sending arbitrary HTTP requests to internal or external destinations.
Business impact
Successful exploitation of this vulnerability can lead to unauthorized access to internal network resources that are otherwise protected by a firewall, potentially exposing sensitive data or internal services. Given the CVSS score of 7.3, this represents a high-risk scenario for organizations relying on HyperChat, as it facilitates lateral movement and reconnaissance within the internal environment.
Remediation
Immediate Action: As no official patch is currently available, administrators should immediately isolate the HyperChat HTTP service from untrusted networks and restrict access to the application.
Proactive Monitoring: Review web access logs for requests containing suspicious baseurl headers or unexpected outbound traffic originating from the server hosting the HyperChat service.
Compensating Controls: Implement strict egress filtering on the server to block traffic to internal subnets and sensitive loopback addresses, and deploy a Web Application Firewall to drop requests containing malicious or unauthorized baseurl header values.
Exploitation status
Public Exploit Available: Yes, a proof of concept and technical reproduction steps are available in the linked GitHub repository issue.
Analyst recommendation
This vulnerability presents a significant risk due to the potential for unauthorized internal network access and the availability of public exploitation details. Organizations currently running HyperChat should treat this as a high priority, applying the recommended network isolation and egress controls immediately until a vendor-supplied patch is released and verified.
Sources
Originally found and disclosed by BruceJin (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.
- VDB-359823 | BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery Vulnerability database entry
- VDB-359823 | CTI Indicators (IOB, IOC, IOA)
- Submit #802265 | BigSweetPotatoStudio HyperChat 2.0.0-alpha.63 Server-Side Request Forgery Third-party advisory
- Exploit / PoC
- github.com