CVE-2024-9107
CVSS 3.0 Score 6.8 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 79
Summary
CVE-2024-9107 is a stored cross-site scripting (XSS) vulnerability affecting the gaizhenbiao/chuanhuchatgpt repository, specifically version 20b2e02 of Git. The issue arises due to improper sanitization of HTML tags within chat history uploads. The sanitization logic fails to adequately handle HTML tags within code blocks, enabling attackers to inject malicious scripts. This vulnerability can lead to the execution of arbitrary JavaScript code in the context of the user's browser, potentially jeopardizing sensitive information or leading to identity theft.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.