Skip to main content

Vendor archive

gaizhenbiao CVEs

Beta · best-effort

31 CVEs tagged to vendor gaizhenbiao6 Critical, 12 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2025-0191

Published Mar 20, 2025

A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to improper handling of form-dat…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0188

Published Mar 20, 2025

A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacker to construct a response link…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-9216

Published Mar 20, 2025

An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerabilit…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9159

Published Mar 20, 2025

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a co…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9107

Published Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper saniti…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8613

Published Mar 20, 2025

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8400

Published Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10955

Published Mar 20, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02. The server uses the regex pattern `r'<[^>]+>'` to parse us…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10707

Published Mar 20, 2025

gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, which has a known issue (CVE-202…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10650

Published Mar 20, 2025

An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could be exploited by sending large data payloads using a multipa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48059

Published Nov 4, 2024

gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious conte…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8143

Published Oct 29, 2024

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. Wh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7962

Published Oct 29, 2024

An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7807

Published Oct 29, 2024

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of charact…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5982

Published Oct 29, 2024

A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5823

Published Oct 29, 2024

A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical c…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6255

Published Jul 31, 2024

A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration fi…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6035

Published Jul 11, 2024

A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attacker to inject malicious JavaScript code…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6037

Published Jul 10, 2024

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir).…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6036

Published Jul 10, 2024

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6090

Published Jun 27, 2024

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be explo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6038

Published Jun 27, 2024

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history functio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5822

Published Jun 27, 2024

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulner…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5278

Published Jun 6, 2024

gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/upload` endpoint. Specifically…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5124

Published Jun 6, 2024

A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2