Binary-husky

Gpt Academic

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.12%
  • Veröffentlicht 11.09.2025 01:02:07
  • Zuletzt bearbeitet 31.10.2025 14:39:12

A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the component LaTeX File Handler. Such manipulation of the argument \input{} l...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 20.03.2025 10:11:39
  • Zuletzt bearbeitet 15.07.2025 11:15:23

GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 20.03.2025 10:11:36
  • Zuletzt bearbeitet 31.07.2025 19:24:48

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vuln...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 20.03.2025 10:11:21
  • Zuletzt bearbeitet 15.10.2025 13:15:39

A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, wh...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 20.03.2025 10:11:15
  • Zuletzt bearbeitet 14.07.2025 16:40:31

GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exp...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 20.03.2025 10:11:08
  • Zuletzt bearbeitet 29.07.2025 18:49:32

A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the product. An attacker can exploit th...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 20.03.2025 10:10:55
  • Zuletzt bearbeitet 15.10.2025 13:15:38

GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. Despite implementing protections against path traversal, the applicat...

Exploit
  • EPSS 1.05%
  • Veröffentlicht 20.03.2025 10:10:46
  • Zuletzt bearbeitet 15.10.2025 13:15:38

In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. ...

Exploit
  • EPSS 2.17%
  • Veröffentlicht 20.03.2025 10:10:43
  • Zuletzt bearbeitet 31.07.2025 19:32:25

A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation. The Python py7zr package used for extraction does not guarantee that ...

Exploit
  • EPSS 1.04%
  • Veröffentlicht 20.03.2025 10:10:36
  • Zuletzt bearbeitet 14.07.2025 17:20:24

In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause is the execution of user-provided prompts that generate untrusted code without a sandbox, allowing t...