PT-2025-12051 · Unknown+1 · Chuanhuchatgpt+1

Published

2025-03-20

·

Updated

2025-07-14

·

CVE-2024-10650

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ChuanhuChatGPT version 20240918
Description A Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT, which could be exploited by sending large data payloads using a multipart boundary. Although a patch was applied for a previous issue, the problem can still be exploited by sending data in groups of 10 characters per line, with multiple lines. This can cause the system to continuously process these characters, resulting in prolonged unavailability of the service. The exploitation now requires low privilege if authentication is enabled due to a version upgrade in Gradio.
Recommendations As a temporary workaround, consider restricting the size of data payloads that can be sent to the system to prevent exploitation. Restrict access to the multipart boundary feature to minimize the risk of exploitation. Avoid sending data in groups of 10 characters per line, with multiple lines, until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2024-10650
PYSEC-2025-92

Affected Products

Chuanhuchatgpt
Gradio