PYSEC-2024-319

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/chuanhuchatgpt/PYSEC-2024-319.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2024-319
Aliases
Published
2024-06-27T19:15:19Z
Modified
2026-07-13T07:15:21Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in .json on the target system, leading to a denial of service as users are unable to authenticate.

References

Affected packages

PyPI / chuanhuchatgpt

Package

Name
chuanhuchatgpt
View open source insights on deps.dev
Purl
pkg:pypi/chuanhuchatgpt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
20240410

Affected versions

3.*
3.2.5

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/chuanhuchatgpt/PYSEC-2024-319.yaml"