Gaizhenbiao develops the ChuanhuChatGPT application, a web-based interface for interacting with large language models that has attracted significant attention in the vulnerability landscape. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across input-handling and access-control boundaries including cross-site scripting, path traversal, improper resource throttling, and authorization flaws. The exposure reflects common risks in rapidly developed web applications that integrate external AI services and handle user input at scale, where insufficient validation and access controls can expose both application functionality and underlying model access to compromise. Defenders deploying or exposing this application should prioritize input validation hardening, rate-limiting mechanisms, and access-control audits; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gaizhenbiao over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3234CRITICAL The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user acc | Jun 6, 2024 | 9.8 | 45 | NO | YES |
CVE-2024-5982CRITICAL A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including | Oct 29, 2024 | 9.8 | 43 | NO | NO |
CVE-2024-6255CRITICAL A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration fil | Jul 31, 2024 | 9.1 | 30 | NO | NO |
CVE-2024-6037CRITICAL A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). | Jul 10, 2024 | 9.1 | 29 | NO | NO |
CVE-2024-6036CRITICAL A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_ | Jul 10, 2024 | 9.1 | 29 | NO | NO |
CVE-2024-5822CRITICAL A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnera | Jun 27, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-5823CRITICAL A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical co | Oct 29, 2024 | 9.1 | 24 | NO | NO |
CVE-2024-8613HIGH A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling | Mar 20, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-9216HIGH An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerability | Mar 20, 2025 | 8.1 | 22 | NO | NO |
CVE-2024-6090HIGH A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploi | Jun 27, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gaizhenbiao.
Media articles that mention a CVE ID that affects a product developed by Gaizhenbiao — matched by CVE ID, not by vendor name.