{"id":"CVE-2024-6037","aliases":["PYSEC-2024-317"],"title":"A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the serv…","summary":"A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resul…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","vendor":"chuanhuchatgpt","product":"chuanhuchatgpt","ecosystem":"pip","affected":["chuanhuchatgpt <= 20240410"],"published":"2024-07-10","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/PYSEC-2024-317","references":[{"url":"https://github.com/gaizhenbiao/chuanhuchatgpt/commit/71cb89c4c948dae5aaa0ae64b98f98e3965bdb37"},{"url":"https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e"}],"tags":["osv","pip"],"epss":0.10693,"epssPercentile":0.95675,"ingestedAt":"2026-07-13T18:58:06.371Z","slug":"CVE-2024-6037","body":"## Overview\n\nA vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.\n\n## Affected packages\n\n- `chuanhuchatgpt <= 20240410`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":50.1,"likelihood":2.1,"exploitation":0,"ransomware":0},"changes":[]}