CVE-2024-10954
- EPSS 1.26%
- Veröffentlicht 20.03.2025 10:10:46
- Zuletzt bearbeitet 15.10.2025 13:15:38
In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. ...
CVE-2024-12389
- EPSS 2.6%
- Veröffentlicht 20.03.2025 10:10:43
- Zuletzt bearbeitet 31.07.2025 19:32:25
A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation. The Python py7zr package used for extraction does not guarantee that ...
CVE-2024-10950
- EPSS 1.25%
- Veröffentlicht 20.03.2025 10:10:36
- Zuletzt bearbeitet 14.07.2025 17:20:24
In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause is the execution of user-provided prompts that generate untrusted code without a sandbox, allowing t...
CVE-2024-12390
- EPSS 2.6%
- Veröffentlicht 20.03.2025 10:10:36
- Zuletzt bearbeitet 15.10.2025 13:15:40
A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The Python rarfile module, which supports symlinks, can b...
CVE-2024-10714
- EPSS 0.26%
- Veröffentlicht 20.03.2025 10:10:35
- Zuletzt bearbeitet 15.10.2025 13:15:36
A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the end of a multipart boundary during file upload. This results in the server continuously processing e...
CVE-2024-12391
- EPSS 0.23%
- Veröffentlicht 20.03.2025 10:10:33
- Zuletzt bearbeitet 15.10.2025 13:15:40
A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (ReDoS) attack. The function '解析项目源码(手动指定和筛选源码文件类型)' permits the execution of user-provided regular expressions. Certain regular exp...
CVE-2024-11033
- EPSS 0.07%
- Veröffentlicht 20.03.2025 10:10:30
- Zuletzt bearbeitet 14.07.2025 16:52:03
A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit ...
CVE-2024-10819
- EPSS 0.08%
- Veröffentlicht 20.03.2025 10:10:26
- Zuletzt bearbeitet 14.07.2025 15:05:59
A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to unauthorized file uploads and pot...
CVE-2025-0183
- EPSS 0.06%
- Veröffentlicht 20.03.2025 10:10:24
- Zuletzt bearbeitet 01.08.2025 01:53:16
A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inject malicious scripts into the `debug_log.html` file generated by the m...
CVE-2024-12388
- EPSS 0.1%
- Veröffentlicht 20.03.2025 10:10:05
- Zuletzt bearbeitet 15.10.2025 13:15:40
A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user input, which can take polynomial time to match certain crafted inpu...