PYSEC-2025-239

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/chuanhuchatgpt/PYSEC-2025-239.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2025-239
Aliases
Published
2025-03-20T10:15:43Z
Modified
2026-07-13T07:15:21Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate chat histories of other users.

References

Affected packages

PyPI / chuanhuchatgpt

Package

Name
chuanhuchatgpt
View open source insights on deps.dev
Purl
pkg:pypi/chuanhuchatgpt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
20240802

Affected versions

3.*
3.2.5

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/chuanhuchatgpt/PYSEC-2025-239.yaml"