PYSEC-2024-73

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/chuanhuchatgpt/PYSEC-2024-73.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2024-73
Aliases
Published
2024-07-31T01:15:00Z
Modified
2024-08-27T15:41:59.449837Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as config.json and ds_config_chatbot.json. This issue arises due to improper validation of file paths, enabling directory traversal attacks. An attacker can exploit this vulnerability to disrupt the functioning of the system, manipulate settings, or potentially cause data loss or corruption.

References

Affected packages

PyPI / chuanhuchatgpt

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.2.5