CVE-2024-3234 is a critical path traversal vulnerability (CVSS 9.8) affecting the gaizhenbiao/chuanhuchatgpt application, specifically versions prior to 20240305. This flaw, caused by an outdated Gradio component, allows unauthenticated attackers to bypass security restrictions and access sensitive files like API keys, leading to high confidentiality, integrity, and availability impact. While not yet in CISA KEV, this vulnerability is on the Hot List and has a very high EPSS score, indicating a significant likelihood of future exploitation. Publicly available Nuclei exploit templates exist, and it has received community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20240305CPE matchmatch criteria | cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.