Junglewise Threat Intelligence

CVE-2024-6037: PYSEC-2024-317 - A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server

CVE-2024-6037 · Severity: low · CVSS 3.1 · Published 2024-07-10

Technologies: chuanhuchatgpt (PyPI). Vendors: PyPI.

Executive brief

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption.

Affected products

  • PyPI chuanhuchatgpt

Related threats