CVE-2024-10707

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 20

Summary

CVE-2024-10707 is a new vulnerability affecting the chuanhuchatgpt project by gaizhenbiao, specifically the git commit d4ec6a3. This issue involves a local file inclusion vulnerability caused by the application's use of the gradio component, gr.JSON (CVE-2024-4941). Unauthenticated users can take advantage of this vulnerability by uploading a maliciously crafted JSON file, which is then incorrectly processed in the handle_dataset_selection function, allowing them to access arbitrary files on the server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share