---
id: CVE-2024-6037
aliases:
  - PYSEC-2024-317
title: >-
  A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an
  attacker to create arbitrary folders at any location on the serv…
summary: >-
  A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an
  attacker to create arbitrary folders at any location on the server, including
  the root directory (C: dir). This can lead to uncontrolled resource
  consumption, resul…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
vendor: chuanhuchatgpt
product: chuanhuchatgpt
ecosystem: pip
affected:
  - chuanhuchatgpt <= 20240410
published: '2024-07-10'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2024-317'
references:
  - url: >-
      https://github.com/gaizhenbiao/chuanhuchatgpt/commit/71cb89c4c948dae5aaa0ae64b98f98e3965bdb37
  - url: 'https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e'
tags:
  - osv
  - pip
epss: 0.10693
epssPercentile: 0.95612
ingestedAt: '2026-07-13T18:58:06.371Z'
---

## Overview

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.

## Affected packages

- `chuanhuchatgpt <= 20240410`

## Remediation

Refer to the advisory for the patched release.
