---
id: CVE-2024-8613
aliases:
  - PYSEC-2025-239
title: >-
  A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows
  attackers to access, copy, and delete other users' chat histories. …
summary: >-
  A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows
  attackers to access, copy, and delete other users' chat histories. This issue
  arises due to improper handling of session data and lack of access control
  mechanisms, en…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: chuanhuchatgpt
product: chuanhuchatgpt
ecosystem: pip
affected:
  - chuanhuchatgpt <= 20240802
published: '2025-03-20'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2025-239'
references:
  - url: >-
      https://github.com/gaizhenbiao/chuanhuchatgpt/commit/526c615c437377ee9c71f866fd0f19011910f705
  - url: 'https://huntr.com/bounties/76258774-b011-4044-9c3d-c2609b1cbd29'
tags:
  - osv
  - pip
epss: 0.00588
epssPercentile: 0.46865
ingestedAt: '2026-07-13T18:58:06.608Z'
---

## Overview

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate chat histories of other users.

## Affected packages

- `chuanhuchatgpt <= 20240802`

## Remediation

Refer to the advisory for the patched release.
