{"schema_version":1,"title":"chuanhuchatgpt (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 21 vulnerabilities in chuanhuchatgpt (PyPI): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-0191, was published on 20 March 2025.","url":"https://junglewise.ai/threats/technologies/chuanhuchatgpt","json_url":"https://junglewise.ai/threats/technologies/chuanhuchatgpt.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/chuanhuchatgpt","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":21,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2025-0191","cvss":3,"epss":0.0059,"slug":"cve-2025-0191-pysec-2025-99-a-denial-of-service-dos-vulnerability-exists-in-the","title":"PYSEC-2025-99 - A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:51.907+00:00","url":"https://junglewise.ai/threats/cve-2025-0191-pysec-2025-99-a-denial-of-service-dos-vulnerability-exists-in-the"},{"cve":"CVE-2025-0188","cvss":3,"epss":0.0048,"slug":"cve-2025-0188-pysec-2025-98-a-server-side-request-forgery-ssrf-vulnerability-was","title":"PYSEC-2025-98 - A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows a","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:51.533+00:00","url":"https://junglewise.ai/threats/cve-2025-0188-pysec-2025-98-a-server-side-request-forgery-ssrf-vulnerability-was"},{"cve":"CVE-2024-9216","cvss":3,"epss":0.0062,"slug":"cve-2024-9216-pysec-2025-97-an-authentication-bypass-vulnerability-exists-in","title":"PYSEC-2025-97 - An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete othe","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:47.477+00:00","url":"https://junglewise.ai/threats/cve-2024-9216-pysec-2025-97-an-authentication-bypass-vulnerability-exists-in"},{"cve":"CVE-2024-9159","cvss":3,"epss":0.0064,"slug":"cve-2024-9159-pysec-2025-96-an-incorrect-authorization-vulnerability-exists-in","title":"PYSEC-2025-96 - An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to rest","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:47.353+00:00","url":"https://junglewise.ai/threats/cve-2024-9159-pysec-2025-96-an-incorrect-authorization-vulnerability-exists-in"},{"cve":"CVE-2024-9107","cvss":3.1,"epss":0.0057,"slug":"cve-2024-9107-pysec-2025-95-a-stored-cross-site-scripting-xss-vulnerability","title":"PYSEC-2025-95 - A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vu","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:47.23+00:00","url":"https://junglewise.ai/threats/cve-2024-9107-pysec-2025-95-a-stored-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2024-8613","cvss":3.1,"epss":0.0059,"slug":"cve-2024-8613-pysec-2025-239-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt","title":"PYSEC-2025-239 - A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. Thi","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:43.473+00:00","url":"https://junglewise.ai/threats/cve-2024-8613-pysec-2025-239-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt"},{"cve":"CVE-2024-10955","cvss":3,"epss":0.0074,"slug":"cve-2024-10955-pysec-2025-94-a-regular-expression-denial-of-service-redos","title":"PYSEC-2025-94 - A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02. The server uses the","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:22.35+00:00","url":"https://junglewise.ai/threats/cve-2024-10955-pysec-2025-94-a-regular-expression-denial-of-service-redos"},{"cve":"CVE-2024-10707","cvss":3,"epss":0.0073,"slug":"cve-2024-10707-pysec-2025-93-gaizhenbiao-chuanhuchatgpt-version-git-d4ec6a3-is","title":"PYSEC-2025-93 - gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:18.28+00:00","url":"https://junglewise.ai/threats/cve-2024-10707-pysec-2025-93-gaizhenbiao-chuanhuchatgpt-version-git-d4ec6a3-is"},{"cve":"CVE-2024-10650","cvss":3,"epss":0.0071,"slug":"cve-2024-10650-pysec-2025-92-an-unauthenticated-denial-of-service-dos","title":"PYSEC-2025-92 - An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could be exploited by send","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:18.15+00:00","url":"https://junglewise.ai/threats/cve-2024-10650-pysec-2025-92-an-unauthenticated-denial-of-service-dos"},{"cve":"CVE-2024-8143","cvss":3.1,"epss":0.0049,"slug":"cve-2024-8143-pysec-2024-113-in-the-latest-version-20240628-of-gaizhenbiao","title":"PYSEC-2024-113 - In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to acc","severity":"low","exploited":false,"published_at":"2024-10-29T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-8143-pysec-2024-113-in-the-latest-version-20240628-of-gaizhenbiao"},{"cve":"CVE-2024-7807","cvss":3.1,"epss":0.0063,"slug":"cve-2024-7807-pysec-2024-119-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt","title":"PYSEC-2024-119 - A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an att","severity":"low","exploited":false,"published_at":"2024-10-29T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-7807-pysec-2024-119-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt"},{"cve":"CVE-2024-7962","cvss":3.1,"epss":0.0079,"slug":"cve-2024-7962-pysec-2024-112-an-arbitrary-file-read-vulnerability-exists-in","title":"PYSEC-2024-112 - An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading promp","severity":"low","exploited":false,"published_at":"2024-10-29T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-7962-pysec-2024-112-an-arbitrary-file-read-vulnerability-exists-in"},{"cve":"CVE-2024-6255","cvss":3.1,"epss":0.1309,"slug":"cve-2024-6255-pysec-2024-73-a-vulnerability-in-the-json-file-handling-of","title":"PYSEC-2024-73 - A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the serv","severity":"low","exploited":false,"published_at":"2024-07-31T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-6255-pysec-2024-73-a-vulnerability-in-the-json-file-handling-of"},{"cve":"CVE-2024-6035","cvss":3.1,"epss":0.0037,"slug":"cve-2024-6035-pysec-2024-61-a-stored-cross-site-scripting-xss-vulnerability","title":"PYSEC-2024-61 - A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attack","severity":"low","exploited":false,"published_at":"2024-07-11T11:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-6035-pysec-2024-61-a-stored-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2024-6037","cvss":3.1,"epss":0.1069,"slug":"cve-2024-6037-pysec-2024-317-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt","title":"PYSEC-2024-317 - A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server","severity":"low","exploited":false,"published_at":"2024-07-10T23:15:14.493+00:00","url":"https://junglewise.ai/threats/cve-2024-6037-pysec-2024-317-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt"},{"cve":"CVE-2024-6036","cvss":3.1,"epss":0.1094,"slug":"cve-2024-6036-pysec-2024-269-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt","title":"PYSEC-2024-269 - A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request t","severity":"low","exploited":false,"published_at":"2024-07-10T23:15:14.227+00:00","url":"https://junglewise.ai/threats/cve-2024-6036-pysec-2024-269-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt"},{"cve":"CVE-2024-6090","cvss":3,"epss":0.0086,"slug":"cve-2024-6090-pysec-2024-319-a-path-traversal-vulnerability-exists-in","title":"PYSEC-2024-319 - A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat historie","severity":"low","exploited":false,"published_at":"2024-06-27T19:15:19.777+00:00","url":"https://junglewise.ai/threats/cve-2024-6090-pysec-2024-319-a-path-traversal-vulnerability-exists-in"},{"cve":"CVE-2024-6038","cvss":3,"epss":0.0066,"slug":"cve-2024-6038-pysec-2024-318-a-regular-expression-denial-of-service-redos","title":"PYSEC-2024-318 - A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability i","severity":"low","exploited":false,"published_at":"2024-06-27T19:15:19.04+00:00","url":"https://junglewise.ai/threats/cve-2024-6038-pysec-2024-318-a-regular-expression-denial-of-service-redos"},{"cve":"CVE-2024-5822","cvss":3.1,"epss":0.0053,"slug":"cve-2024-5822-pysec-2024-268-a-server-side-request-forgery-ssrf-vulnerability","title":"PYSEC-2024-268 - A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= Chuan","severity":"low","exploited":false,"published_at":"2024-06-27T19:15:16.88+00:00","url":"https://junglewise.ai/threats/cve-2024-5822-pysec-2024-268-a-server-side-request-forgery-ssrf-vulnerability"},{"cve":"CVE-2024-4321","cvss":3,"epss":0.006,"slug":"cve-2024-4321-pysec-2024-267-a-local-file-inclusion-lfi-vulnerability-exists-in","title":"PYSEC-2024-267 - A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for u","severity":"low","exploited":false,"published_at":"2024-05-16T09:15:16.327+00:00","url":"https://junglewise.ai/threats/cve-2024-4321-pysec-2024-267-a-local-file-inclusion-lfi-vulnerability-exists-in"},{"cve":"CVE-2024-2217","cvss":3,"epss":0.0079,"slug":"cve-2024-2217-pysec-2024-316-gaizhenbiao-chuanhuchatgpt-is-vulnerable-to","title":"PYSEC-2024-316 - gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerabil","severity":"low","exploited":false,"published_at":"2024-04-10T17:15:54.44+00:00","url":"https://junglewise.ai/threats/cve-2024-2217-pysec-2024-316-gaizhenbiao-chuanhuchatgpt-is-vulnerable-to"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"chuanhuchatgpt (PyPI)","slug":"chuanhuchatgpt","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/chuanhuchatgpt"},"most_severe":[{"cve":"CVE-2024-6255","cvss":3.1,"epss":0.1309,"slug":"cve-2024-6255-pysec-2024-73-a-vulnerability-in-the-json-file-handling-of","title":"PYSEC-2024-73 - A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the serv","severity":"low","exploited":false,"published_at":"2024-07-31T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-6255-pysec-2024-73-a-vulnerability-in-the-json-file-handling-of"},{"cve":"CVE-2024-6036","cvss":3.1,"epss":0.1094,"slug":"cve-2024-6036-pysec-2024-269-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt","title":"PYSEC-2024-269 - A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request t","severity":"low","exploited":false,"published_at":"2024-07-10T23:15:14.227+00:00","url":"https://junglewise.ai/threats/cve-2024-6036-pysec-2024-269-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt"},{"cve":"CVE-2024-6037","cvss":3.1,"epss":0.1069,"slug":"cve-2024-6037-pysec-2024-317-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt","title":"PYSEC-2024-317 - A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server","severity":"low","exploited":false,"published_at":"2024-07-10T23:15:14.493+00:00","url":"https://junglewise.ai/threats/cve-2024-6037-pysec-2024-317-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt"},{"cve":"CVE-2024-7962","cvss":3.1,"epss":0.0079,"slug":"cve-2024-7962-pysec-2024-112-an-arbitrary-file-read-vulnerability-exists-in","title":"PYSEC-2024-112 - An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading promp","severity":"low","exploited":false,"published_at":"2024-10-29T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-7962-pysec-2024-112-an-arbitrary-file-read-vulnerability-exists-in"},{"cve":"CVE-2024-7807","cvss":3.1,"epss":0.0063,"slug":"cve-2024-7807-pysec-2024-119-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt","title":"PYSEC-2024-119 - A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an att","severity":"low","exploited":false,"published_at":"2024-10-29T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-7807-pysec-2024-119-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt"},{"cve":"CVE-2024-8613","cvss":3.1,"epss":0.0059,"slug":"cve-2024-8613-pysec-2025-239-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt","title":"PYSEC-2025-239 - A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. Thi","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:43.473+00:00","url":"https://junglewise.ai/threats/cve-2024-8613-pysec-2025-239-a-vulnerability-in-gaizhenbiao-chuanhuchatgpt"},{"cve":"CVE-2024-9107","cvss":3.1,"epss":0.0057,"slug":"cve-2024-9107-pysec-2025-95-a-stored-cross-site-scripting-xss-vulnerability","title":"PYSEC-2025-95 - A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vu","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:47.23+00:00","url":"https://junglewise.ai/threats/cve-2024-9107-pysec-2025-95-a-stored-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2024-5822","cvss":3.1,"epss":0.0053,"slug":"cve-2024-5822-pysec-2024-268-a-server-side-request-forgery-ssrf-vulnerability","title":"PYSEC-2024-268 - A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= Chuan","severity":"low","exploited":false,"published_at":"2024-06-27T19:15:16.88+00:00","url":"https://junglewise.ai/threats/cve-2024-5822-pysec-2024-268-a-server-side-request-forgery-ssrf-vulnerability"},{"cve":"CVE-2024-8143","cvss":3.1,"epss":0.0049,"slug":"cve-2024-8143-pysec-2024-113-in-the-latest-version-20240628-of-gaizhenbiao","title":"PYSEC-2024-113 - In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to acc","severity":"low","exploited":false,"published_at":"2024-10-29T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-8143-pysec-2024-113-in-the-latest-version-20240628-of-gaizhenbiao"},{"cve":"CVE-2024-6035","cvss":3.1,"epss":0.0037,"slug":"cve-2024-6035-pysec-2024-61-a-stored-cross-site-scripting-xss-vulnerability","title":"PYSEC-2024-61 - A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attack","severity":"low","exploited":false,"published_at":"2024-07-11T11:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-6035-pysec-2024-61-a-stored-cross-site-scripting-xss-vulnerability"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}