PT-2025-12304 · Unknown · Gaizhenbiao/Chuanhuchatgpt

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2025-0188

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions gaizhenbiao/chuanhuchatgpt version 20240914
Description A Server-Side Request Forgery (SSRF) issue was discovered, allowing an attacker to construct a response link by saving the response in a folder named after the SHA-1 hash of the target URL. This enables the attacker to access the response directly, potentially leading to unauthorized access to internal systems, data theft, service disruption, or further attacks such as port scanning and accessing metadata endpoints.
Recommendations For gaizhenbiao/chuanhuchatgpt version 20240914, consider restricting access to the response folder to minimize the risk of exploitation. As a temporary workaround, avoid using the SHA-1 hash of the target URL as a folder name until a patch is available. Restrict access to metadata endpoints to prevent further attacks.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0188
PYSEC-2025-98

Affected Products

Gaizhenbiao/Chuanhuchatgpt