GHSA-r2jq-4h3x-rfj6
MODERATECVE-2026-7223A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/aiProxyMiddleware.mts of the component AI Proxy Middleware. Such manipulation of the argument baseurl leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The
- Affected
- <= 2.0.0-alpha.63
- Fixed in
- not stated
- Weakness
- CWE-918
- Published
- 2026-04-28
- Source
- github