HIGH8.8
PYSEC-2025-239
Details
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate chat histories of other users.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/chuanhuchatgpt
Introduced in:
0No fixed version published yet for chuanhuchatgpt (pip). Pin to a known-safe version or switch to an alternative.