Junglewise Threat Intelligence

CVE-2024-5822: PYSEC-2024-268 - A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= Chuan

CVE-2024-5822 · Severity: low · CVSS 3.1 · Published 2024-06-27

Technologies: chuanhuchatgpt (PyPI). Vendors: PyPI.

Executive brief

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the vulnerable server to internal or external resources, potentially bypassing security controls and accessing sensitive data.

Affected products

  • PyPI chuanhuchatgpt

Related threats