📦 Chuanhuchatgpt

by Gaizhenbiao

🔍 What is Chuanhuchatgpt?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-5823

CRITICAL CVSS 9.1 Oct 29, 2024

This vulnerability allows attackers to overwrite critical configuration files in gaizhenbiao/chuanhuchatgpt, potentially altering system behavior, security settings, or causing denial of service. User...

CVE-2024-6036

CRITICAL CVSS 9.1 Jul 10, 2024

This vulnerability in gaizhenbiao/chuanhuchatgpt allows any user to restart the server by sending a specific request to the /queue/join? endpoint with fn_index:66. This can cause service disruption, d...

CVE-2024-5822

CRITICAL CVSS 9.8 Jun 27, 2024

This SSRF vulnerability in ChuanhuChatGPT's upload processing interface allows attackers to make the server send requests to internal or external resources, potentially accessing sensitive data or byp...

CVE-2024-9216

HIGH CVSS 8.1 Mar 20, 2025

This authentication bypass vulnerability in ChuanhuChatGPT allows attackers to read and delete other users' chat histories by manipulating username parameters in HTTP requests. Any deployment of the a...

CVE-2024-7962

HIGH CVSS 7.5 Oct 29, 2024

An arbitrary file read vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows attackers to read sensitive files on the server by exploiting insufficient validation of prompt template file...

CVE-2024-6255

HIGH CVSS 8.2 Jul 31, 2024

This vulnerability allows any user to delete any JSON file on the server through directory traversal attacks due to improper path validation. It affects gaizhenbiao/chuanhuchatgpt version 20240410, po...

CVE-2024-6090

HIGH CVSS 7.5 Jun 27, 2024

A path traversal vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete other users' chat histories and any .json files on the system. This can cause denial of service ...

CVE-2024-5124

HIGH CVSS 7.5 Jun 6, 2024

This timing attack vulnerability in gaizhenbiao/chuanhuchatgpt allows attackers to guess passwords by measuring how long password comparisons take. Attackers can exploit this to compromise user accoun...

CVE-2024-4520

HIGH CVSS 7.5 Jun 4, 2024

This CVE-2024-4520 vulnerability allows any user on the gaizhenbiao/chuanhuchatgpt server to access other users' chat histories without authorization. It affects all users of version 20240410 of this ...

CVE-2024-4321

HIGH CVSS 7.5 May 16, 2024

A Local File Inclusion vulnerability in gaizhenbiao/chuanhuchatgpt version 20240310 allows attackers to read arbitrary files on the server by manipulating the 'name' parameter during chat history uplo...

CVE-2025-0191

MEDIUM CVSS 6.5 Mar 20, 2025

A Denial of Service vulnerability in gaizhenbiao/chuanhuchatgpt allows attackers to crash the service by uploading files with excessively long filenames. This affects all users running version 2024091...

CVE-2025-0188

MEDIUM CVSS 6.5 Mar 20, 2025

A Server-Side Request Forgery (SSRF) vulnerability in gaizhenbiao/chuanhuchatgpt allows attackers to make the application send requests to internal systems by manipulating URL responses. This affects ...

CVE-2024-9107

MEDIUM CVSS 5.4 Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability in the gaizhenbiao/chuanhuchatgpt repository allows attackers to inject malicious JavaScript via improperly sanitized HTML tags in chat history upload...

CVE-2024-10955

MEDIUM CVSS 6.5 Mar 20, 2025

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in gaizhenbiao/chuanhuchatgpt where a regex pattern used to parse user input can be exploited to cause excessive CPU con...

CVE-2024-10707

MEDIUM CVSS 6.5 Mar 20, 2025

This vulnerability allows unauthenticated attackers to read arbitrary files on servers running vulnerable versions of gaizhenbiao/chuanhuchatgpt. The issue stems from improper input validation in the ...

CVE-2024-6035

MEDIUM CVSS 6.1 Jul 11, 2024

A stored XSS vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows attackers to inject malicious JavaScript into chat history files. When victims upload these files, the script executes ...

CVE-2024-5278

MEDIUM CVSS 6.1 Jun 6, 2024

This vulnerability allows attackers to upload malicious files to the gaizhenbiao/chuanhuchatgpt application due to insufficient file validation. Attackers can upload HTML files with XSS payloads or Py...

CVE-2024-3404

MEDIUM CVSS 6.5 Jun 6, 2024

This vulnerability allows authenticated attackers to bypass access controls and read other users' chat history files in the gaizhenbiao/chuanhuchatgpt application. It affects users of version 20240121...