CVE-2026-7223Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/aiProxyMiddleware.mts of the component AI Proxy Middleware. Such manipulation of the argument baseurl leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-29)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-28: 1Mentions · 2026-04-29: 204-2804-29
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-281
General1
2026-04-292
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7223 A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/a… https://www.cve.org/CVERecord?id=CVE-2026-7223 ----- Traducción: CVE-2026-7223 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑7223 for BigSweetPotatoStudio HyperChat up to 2.0.0‑alpha.63, providing minimal technical details and no PoC, exploit, or patch information.

    0000035
    73 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7223 A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/a… https://www.cve.org/CVERecord?id=CVE-2026-7223

    Post summary

    The announcement identifies CVE-2026-7223 in BigSweetPotatoStudio HyperChat, noting the affected function and file, and links to the CVE record, but provides no further technical, exploit, or mitigation details.

    00000160
    57.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-7223 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7223 #CVE-2026-7223 #CVE #High #CyberSecurity #InfoSec https://t.co/yXzgtfd13S

    Post summary

    The tweet merely announces CVE‑2026‑7223, notes a severity score of 7.3, and links to the NVD record, without providing additional details.

    0000075
    142 followersView on X

Explore more