Path Traversal Vulnerability in ChuanhuChatGPT by GaizhenBiao
CVE-2024-5982
What is CVE-2024-5982?
A path traversal vulnerability exists in ChuanhuChatGPT due to improper handling of unsanitized input across various functionalities, including user uploads and directory management. Specifically, the load_chat_history function in modules/models/base_model.py is susceptible to arbitrary file uploads, enabling potential remote code execution. Additionally, the get_history_names function in utils.py allows for arbitrary directory creation, while the load_template function can be exploited to reveal contents from CSV files. These vulnerabilities are primarily a result of inadequate sanitization of user inputs combined with the construction of directory paths.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
