CVE-2026-0764
- EPSS 1.54%
- Veröffentlicht 23.01.2026 03:28:27
- Zuletzt bearbeitet 18.02.2026 16:42:46
GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to exploit this ...
CVE-2026-0763
- EPSS 1.69%
- Veröffentlicht 23.01.2026 03:28:23
- Zuletzt bearbeitet 18.02.2026 16:42:19
GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not r...
CVE-2026-0762
- EPSS 0.47%
- Veröffentlicht 23.01.2026 03:28:19
- Zuletzt bearbeitet 18.02.2026 16:41:56
GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Interaction with a malicious DAAS server i...
CVE-2025-10236
- EPSS 0.11%
- Veröffentlicht 11.09.2025 01:02:07
- Zuletzt bearbeitet 31.10.2025 14:39:12
A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the component LaTeX File Handler. Such manipulation of the argument \input{} l...
CVE-2024-10956
- EPSS 0.03%
- Veröffentlicht 20.03.2025 10:11:39
- Zuletzt bearbeitet 15.07.2025 11:15:23
GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server...
CVE-2024-12392
- EPSS 0.09%
- Veröffentlicht 20.03.2025 10:11:36
- Zuletzt bearbeitet 31.07.2025 19:24:48
A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vuln...
CVE-2024-12387
- EPSS 0.08%
- Veröffentlicht 20.03.2025 10:11:21
- Zuletzt bearbeitet 15.10.2025 13:15:39
A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, wh...
CVE-2024-11030
- EPSS 0.07%
- Veröffentlicht 20.03.2025 10:11:15
- Zuletzt bearbeitet 14.07.2025 16:40:31
GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exp...
CVE-2024-10948
- EPSS 0.1%
- Veröffentlicht 20.03.2025 10:11:08
- Zuletzt bearbeitet 29.07.2025 18:49:32
A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the product. An attacker can exploit th...
CVE-2024-10986
- EPSS 0.19%
- Veröffentlicht 20.03.2025 10:10:55
- Zuletzt bearbeitet 15.10.2025 13:15:38
GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. Despite implementing protections against path traversal, the applicat...