Unrated severityNVD Advisory· Published Mar 20, 2025· Updated Oct 15, 2025
Local File Inclusion in gaizhenbiao/chuanhuchatgpt
CVE-2024-10707
Description
gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, which has a known issue (CVE-2024-4941). This vulnerability allows unauthenticated users to access arbitrary files on the server by uploading a specially crafted JSON file and exploiting the improper input validation in the handle_dataset_selection function.
Affected products
2- Range: git d4ec6a3
- gaizhenbiao/gaizhenbiao/chuanhuchatgptv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.