id: PYSEC-2025-93 published: "2025-03-20T10:15:18.280Z" modified: "2025-10-15T13:15:36.567Z" aliases: - CVE-2024-10707 details: gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, which has a known issue (CVE-2024-4941). This vulnerability allows unauthenticated users to access arbitrary files on the server by uploading a specially crafted JSON file and exploiting the improper input validation in the handle_dataset_selection function. affected: - package: name: chuanhuchatgpt ecosystem: PyPI purl: pkg:pypi/chuanhuchatgpt ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: "2024-09-25" ecosystem_specific: {} references: - type: EVIDENCE url: https://huntr.com/bounties/98fdedea-6ad0-4157-b7d2-ae71c9786ee8 severity: - type: CVSS_V3 score: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N