id: PYSEC-2024-317 published: "2024-07-10T23:15:14.493Z" modified: "2026-07-13T05:48:14.244609Z" aliases: - CVE-2024-6037 details: "A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and potential data loss or corruption." affected: - package: name: chuanhuchatgpt ecosystem: PyPI purl: pkg:pypi/chuanhuchatgpt ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: "20240410" versions: - 3.2.5 ecosystem_specific: {} references: - type: FIX url: https://github.com/gaizhenbiao/chuanhuchatgpt/commit/71cb89c4c948dae5aaa0ae64b98f98e3965bdb37 - type: EVIDENCE url: https://huntr.com/bounties/eca6904f-f9fd-40c8-9e85-96f54daf405e severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H