Junglewise Threat Intelligence

CVE-2024-6090: PYSEC-2024-319 - A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat historie

CVE-2024-6090 · Severity: low · CVSS 3 · Published 2024-06-27

Technologies: chuanhuchatgpt (PyPI). Vendors: PyPI.

Executive brief

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to authenticate.

Affected products

  • PyPI chuanhuchatgpt

Related threats