CVE-2024-8143

MEDIUM

gaizhenbiao/chuanhuchatgpt <20240628 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other users. When a user logs in, a directory is created in the history folder with the user's name. By manipulating the /file endpoint, an authenticated user can enumerate and access files in other users' directories, leading to unauthorized access to private chat histories. This vulnerability can be exploited to read any user's private chat history.

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1057
Status published
Products (1)
gaizhenbiao/chuanhuchatgpt 2024-06-28
Published Oct 29, 2024
Tracked Since Feb 18, 2026