CVE-2025-10236
- EPSS 0.12%
- Veröffentlicht 11.09.2025 01:02:07
- Zuletzt bearbeitet 31.10.2025 14:39:12
A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the component LaTeX File Handler. Such manipulation of the argument \input{} l...
CVE-2024-10956
- EPSS 0.03%
- Veröffentlicht 20.03.2025 10:11:39
- Zuletzt bearbeitet 15.07.2025 11:15:23
GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server...
CVE-2024-12392
- EPSS 0.06%
- Veröffentlicht 20.03.2025 10:11:36
- Zuletzt bearbeitet 31.07.2025 19:24:48
A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vuln...
CVE-2024-12387
- EPSS 0.05%
- Veröffentlicht 20.03.2025 10:11:21
- Zuletzt bearbeitet 15.10.2025 13:15:39
A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, wh...
CVE-2024-11030
- EPSS 0.05%
- Veröffentlicht 20.03.2025 10:11:15
- Zuletzt bearbeitet 14.07.2025 16:40:31
GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exp...
CVE-2024-10948
- EPSS 0.07%
- Veröffentlicht 20.03.2025 10:11:08
- Zuletzt bearbeitet 29.07.2025 18:49:32
A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the product. An attacker can exploit th...
CVE-2024-10986
- EPSS 0.12%
- Veröffentlicht 20.03.2025 10:10:55
- Zuletzt bearbeitet 15.10.2025 13:15:38
GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. Despite implementing protections against path traversal, the applicat...
CVE-2024-10954
- EPSS 1.05%
- Veröffentlicht 20.03.2025 10:10:46
- Zuletzt bearbeitet 15.10.2025 13:15:38
In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. ...
CVE-2024-12389
- EPSS 2.17%
- Veröffentlicht 20.03.2025 10:10:43
- Zuletzt bearbeitet 31.07.2025 19:32:25
A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation. The Python py7zr package used for extraction does not guarantee that ...
CVE-2024-10950
- EPSS 1.04%
- Veröffentlicht 20.03.2025 10:10:36
- Zuletzt bearbeitet 14.07.2025 17:20:24
In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause is the execution of user-provided prompts that generate untrusted code without a sandbox, allowing t...