---
id: CVE-2024-6038
aliases:
  - PYSEC-2024-318
title: >-
  A Regular Expression Denial of Service (ReDoS) vulnerability exists in the
  latest version of gaizhenbiao/chuanhuchatgpt. The vulnerabilit…
summary: >-
  A Regular Expression Denial of Service (ReDoS) vulnerability exists in the
  latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in
  the filter_history function within the utils.py module. This function takes a
  user-p…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: chuanhuchatgpt
product: chuanhuchatgpt
ecosystem: pip
affected:
  - chuanhuchatgpt <= 20240410
published: '2024-06-27'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2024-318'
references:
  - url: >-
      https://github.com/gaizhenbiao/chuanhuchatgpt/commit/fcdd5fd6b05ef537a1db185ab115758d87e1ba3f
  - url: 'https://huntr.com/bounties/d41cca0a-82bc-4cbf-a52a-928d304fb42d'
tags:
  - osv
  - pip
epss: 0.00657
epssPercentile: 0.49247
ingestedAt: '2026-07-13T18:58:06.389Z'
---

## Overview

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-provided keyword and attempts to match it against chat history filenames using a regular expression search. Due to the lack of sanitization or validation of the keyword parameter, an attacker can inject a specially crafted regular expression, leading to a denial of service condition. This can cause severe degradation of service performance and potential system unavailability.

## Affected packages

- `chuanhuchatgpt <= 20240410`

## Remediation

Refer to the advisory for the patched release.
