CVE Database · CVE-2024-6090
CVSS v3.1
N/A
EPSS
0.85%
Published
Jun 27, 2024
Modified
Oct 15, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to authenticate.
Weaknesses (CWE)
Affected Products (1)
References (3)