PYSEC-2024-319

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/chuanhuchatgpt/PYSEC-2024-319.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2024-319
Aliases
Published
2024-06-27T19:15:19.777Z
Modified
2026-07-13T07:15:21.771854882Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in .json on the target system, leading to a denial of service as users are unable to authenticate.

References

Affected packages

PyPI / chuanhuchatgpt

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
20240410

Affected versions

3.*
3.2.5

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/chuanhuchatgpt/PYSEC-2024-319.yaml"