CVE-2024-6090

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to authenticate.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:*

History

15 Oct 2025, 13:15

Type Values Removed Values Added
References
  • () https://github.com/gaizhenbiao/chuanhuchatgpt/commit/526c615c437377ee9c71f866fd0f19011910f705 -
CWE CWE-400 CWE-22

15 Jul 2025, 13:25

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:*
First Time Gaizhenbiao
Gaizhenbiao chuanhuchatgpt
References () https://huntr.com/bounties/bd0f8f89-5c8a-4662-89aa-a6861d84cf4c - () https://huntr.com/bounties/bd0f8f89-5c8a-4662-89aa-a6861d84cf4c - Exploit, Third Party Advisory

21 Nov 2024, 09:48

Type Values Removed Values Added
References () https://huntr.com/bounties/bd0f8f89-5c8a-4662-89aa-a6861d84cf4c - () https://huntr.com/bounties/bd0f8f89-5c8a-4662-89aa-a6861d84cf4c -
Summary
  • (es) Existe una vulnerabilidad de path traversal en gaizhenbiao/chuanhuchatgpt versión 20240410, que permite a cualquier usuario eliminar los historiales de chat de otros usuarios. Esta vulnerabilidad también se puede aprovechar para eliminar cualquier archivo que termine en ".json" en el sistema de destino, lo que provoca una denegación de servicio ya que los usuarios no pueden autenticarse.

27 Jun 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-27 19:15

Updated : 2025-10-15 13:15


NVD link : CVE-2024-6090

Mitre link : CVE-2024-6090

CVE.ORG link : CVE-2024-6090


JSON object : View

Products Affected

gaizhenbiao

  • chuanhuchatgpt
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

NVD-CWE-noinfo