Gaizhenbiao
Gaizhenbiao Chuanhuchatgpt: vulnerabilidades y CVE
Gaizhenbiao Chuanhuchatgpt tiene 31 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses0
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-0191 | Media (6.5) | 0.59% | — | 20 mar 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to improper handling of form-data with a large filename in the file… |
| CVE-2025-0188 | Media (6.5) | 0.48% | — | 20 mar 2025 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacker to construct a response link by saving the response in a folder… |
| CVE-2024-9216 | Alta (8.1) | 0.62% | — | 20 mar 2025 | An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerability arises because the username is… |
| CVE-2024-9159 | Media (6.5) | 0.64% | — | 20 mar 2025 | An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue… |
| CVE-2024-9107 | Media (5.4) | 0.57% | — | 20 mar 2025 | A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper sanitization of HTML tags in chat history… |
| CVE-2024-8613 | Alta (8.8) | 0.59% | — | 20 mar 2025 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access… |
| CVE-2024-8400 | Media (5.4) | 0.42% | — | 20 mar 2025 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is… |
| CVE-2024-10955 | Media (6.5) | 0.73% | — | 20 mar 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02. The server uses the regex pattern `r'<[^>]+>'` to parse user input. In Python's default regex… |
| CVE-2024-10707 | Media (6.5) | 0.73% | — | 20 mar 2025 | gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, which has a known issue (CVE-2024-4941). This vulnerability allows… |
| CVE-2024-10650 | Alta (7.5) | 0.71% | — | 20 mar 2025 | An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could be exploited by sending large data payloads using a multipart boundary. Although a patch was… |
| CVE-2024-48059 | Media (6.1) | 0.33% | — | 4 nov 2024 | gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. When a… |
| CVE-2024-8143 | Media (4.3) | 0.49% | — | 29 oct 2024 | In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is… |
| CVE-2024-7962 | Alta (7.5) | 0.79% | — | 29 oct 2024 | An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file that matches specific criteria… |
| CVE-2024-7807 | Alta (7.5) | 0.63% | — | 29 oct 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary,… |
| CVE-2024-5982 | Crítica (9.8) | 31% | — | 29 oct 2024 | A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including user upload, directory creation, and… |
| CVE-2024-5823 | Crítica (9.1) | 0.55% | — | 29 oct 2024 | A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system.… |
| CVE-2024-6255 | Crítica (9.1) | 14% | — | 31 jul 2024 | A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and… |
| CVE-2024-6035 | Media (6.1) | 0.37% | — | 11 jul 2024 | A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attacker to inject malicious JavaScript code into the chat history file. When a… |
| CVE-2024-6037 | Crítica (9.1) | 11% | — | 10 jul 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource… |
| CVE-2024-6036 | Crítica (9.1) | 11% | — | 10 jul 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_index":66`. This unrestricted server… |
| CVE-2024-6090 | Alta (7.5) | 0.86% | — | 27 jun 2024 | A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in… |
| CVE-2024-6038 | Alta (7.5) | 0.66% | — | 27 jun 2024 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This… |
| CVE-2024-5822 | Crítica (9.8) | 0.53% | — | 27 jun 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted… |
| CVE-2024-5278 | Media (6.1) | 0.59% | — | 6 jun 2024 | gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/upload` endpoint. Specifically, the `handle_file_upload` function does… |
| CVE-2024-5124 | Alta (7.5) | 1.4% | — | 6 jun 2024 | A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240310 of the software, where passwords are… |
| CVE-2024-3404 | Media (6.5) | 0.50% | — | 6 jun 2024 | In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access… |
| CVE-2024-3402 | Media (5.4) | 0.46% | — | 6 jun 2024 | A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation efforts,… |
| CVE-2024-3234 | Crítica (9.8) | 3.8% | — | 6 jun 2024 | The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user access to resources within the… |
| CVE-2024-4520 | Alta (7.5) | 0.52% | — | 4 jun 2024 | An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other… |
| CVE-2024-4321 | Alta (7.5) | 0.60% | — | 16 may 2024 | A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper input… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.