VulnSea

chuanhuchatgpt vulnerabilities

CVEs whose affected-version data names the chuanhuchatgpt package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2024-8613High· 8.8
1y ago

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. …

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, en…

Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.59%via OSV
CVE-2024-6037Critical· 9.1
2y ago

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the serv…

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resul…

Midnightchuanhuchatgpt · chuanhuchatgptEPSS 11%via OSV
CVE-2024-6090High· 7.5
2y ago

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histo…

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target s…

Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.86%via OSV
CVE-2024-6038High· 7.5
2y ago

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerabilit…

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-p…

Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.66%via OSV
CVE-2024-2217High· 7.5
2y ago

gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnera…

gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling at…

Twilightchuanhuchatgpt · chuanhuchatgptEPSS 0.78%via OSV
chuanhuchatgpt vulnerabilities (CVEs) · VulnSea