CVE-2024-12390
- EPSS 2.17%
- Veröffentlicht 20.03.2025 10:10:36
- Zuletzt bearbeitet 15.10.2025 13:15:40
A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The Python rarfile module, which supports symlinks, can b...
CVE-2024-10714
- EPSS 0.2%
- Veröffentlicht 20.03.2025 10:10:35
- Zuletzt bearbeitet 15.10.2025 13:15:36
A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the end of a multipart boundary during file upload. This results in the server continuously processing e...
CVE-2024-12391
- EPSS 0.18%
- Veröffentlicht 20.03.2025 10:10:33
- Zuletzt bearbeitet 15.10.2025 13:15:40
A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (ReDoS) attack. The function '解析项目源码(手动指定和筛选源码文件类型)' permits the execution of user-provided regular expressions. Certain regular exp...
CVE-2024-11033
- EPSS 0.06%
- Veröffentlicht 20.03.2025 10:10:30
- Zuletzt bearbeitet 14.07.2025 16:52:03
A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit ...
CVE-2024-10819
- EPSS 0.07%
- Veröffentlicht 20.03.2025 10:10:26
- Zuletzt bearbeitet 14.07.2025 15:05:59
A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to unauthorized file uploads and pot...
CVE-2025-0183
- EPSS 0.04%
- Veröffentlicht 20.03.2025 10:10:24
- Zuletzt bearbeitet 01.08.2025 01:53:16
A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inject malicious scripts into the `debug_log.html` file generated by the m...
CVE-2024-12388
- EPSS 0.08%
- Veröffentlicht 20.03.2025 10:10:05
- Zuletzt bearbeitet 15.10.2025 13:15:40
A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user input, which can take polynomial time to match certain crafted inpu...
CVE-2024-11039
- EPSS 0.5%
- Veröffentlicht 20.03.2025 10:09:58
- Zuletzt bearbeitet 14.07.2025 14:24:11
A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows attackers to achieve remote command execution by deserializ...
CVE-2024-10812
- EPSS 0.31%
- Veröffentlicht 20.03.2025 10:09:24
- Zuletzt bearbeitet 14.07.2025 15:00:54
An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitization. This ca...
CVE-2024-11031
- EPSS 0.05%
- Veröffentlicht 20.03.2025 10:09:16
- Zuletzt bearbeitet 15.07.2025 11:15:23
In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, whi...