{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T14:12:40.806","vulnerabilities":[{"cve":{"id":"CVE-2024-6038","sourceIdentifier":"security@huntr.dev","published":"2024-06-27T19:15:19.040","lastModified":"2026-06-17T08:17:09.450","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-provided keyword and attempts to match it against chat history filenames using a regular expression search. Due to the lack of sanitization or validation of the keyword parameter, an attacker can inject a specially crafted regular expression, leading to a denial of service condition. This can cause severe degradation of service performance and potential system unavailability."},{"lang":"es","value":"Existe una vulnerabilidad de denegación de servicio de expresión regular (ReDoS) en la última versión de gaizhenbiao/chuanhuchatgpt. La vulnerabilidad se encuentra en la función filter_history dentro del módulo utils.py. Esta función toma una palabra clave proporcionada por el usuario e intenta compararla con los nombres de archivos del historial de chat mediante una búsqueda de expresión regular. Debido a la falta de sanitización o validación del parámetro de palabra clave, un atacante puede inyectar una expresión regular especialmente manipulada, lo que lleva a una condición de denegación de servicio. Esto puede provocar una degradación grave del rendimiento del servicio y una posible indisponibilidad del sistema."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"gaizhenbiao","product":"gaizhenbiao/chuanhuchatgpt","versions":[{"version":"unspecified","lessThan":"20240918","versionType":"custom","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"gaizhenbiao","product":"chuanhuchatgpt","defaultStatus":"unknown","cpes":["cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:-:*:*:*:*:*:*:*"],"versions":[{"version":"0","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-28T15:11:23.458775Z","id":"CVE-2024-6038","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]},{"source":"nvd@nist.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:*","matchCriteriaId":"8897AB54-62A0-416D-9A95-BC1F9C705F78"}]}]}],"references":[{"url":"https://github.com/gaizhenbiao/chuanhuchatgpt/commit/fcdd5fd6b05ef537a1db185ab115758d87e1ba3f","source":"security@huntr.dev"},{"url":"https://huntr.com/bounties/d41cca0a-82bc-4cbf-a52a-928d304fb42d","source":"security@huntr.dev","tags":["Exploit","Third Party Advisory"]},{"url":"https://huntr.com/bounties/d41cca0a-82bc-4cbf-a52a-928d304fb42d","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}