CVE-2024-7962

Source
https://cve.org/CVERecord?id=CVE-2024-7962
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7962.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-7962
Aliases
Published
2024-10-29T12:47:58.697Z
Modified
2026-07-15T01:49:06.574898590Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Arbitrary File Read via Insufficient Validation in gaizhenbiao/chuanhuchatgpt
Details

An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria using an absolute path. The file must not have a .json extension and, except for the first line, every other line must contain commas. This vulnerability allows reading parts of format-compliant files, including code and log files, which may contain highly sensitive information such as account credentials.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7962.json",
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-29"
    ]
}
References

Affected packages

Git / github.com/gaizhenbiao/chuanhuchatgpt

Affected ranges

Type
GIT
Repo
https://github.com/gaizhenbiao/chuanhuchatgpt
Events
Database specific
{
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "20240628"
        },
        {
            "last_affected": "20240628"
        }
    ],
    "cpe": "cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240628:*:*:*:*:*:*:*"
}

Affected versions

Other
20240628
20240802
20240914

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7962.json"