Binary-husky
Binary-husky GPT Academic: vulnerabilidades y CVE
Binary-husky GPT Academic tiene 29 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses3
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-0764 | Crítica (9.8) | 1.3% | — | 23 ene 2026 | GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication… |
| CVE-2026-0763 | Crítica (9.8) | 1.3% | — | 23 ene 2026 | GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT… |
| CVE-2026-0762 | Alta (8.1) | 0.76% | — | 23 ene 2026 | GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Interaction… |
| CVE-2025-10236 | Baja (2.1) | 0.76% | — | 11 sept 2025 | A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the component LaTeX File Handler. Such… |
| CVE-2025-0183 | Media (5.4) | 0.40% | — | 20 mar 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inject malicious scripts into the… |
| CVE-2024-12392 | Media (6.5) | 0.60% | — | 20 mar 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An… |
| CVE-2024-12391 | Media (6.5) | 0.95% | — | 20 mar 2025 | A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (ReDoS) attack. The function '解析项目源码(手动指定和筛选源码文件类型)' permits the execution of user-provided regular… |
| CVE-2024-12390 | Alta (8.8) | 1.7% | — | 20 mar 2025 | A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The Python rarfile module,… |
| CVE-2024-12389 | Alta (8.8) | 1.7% | — | 20 mar 2025 | A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation. The Python py7zr package used for… |
| CVE-2024-12388 | Media (6.5) | 0.73% | — | 20 mar 2025 | A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user input, which can take polynomial… |
| CVE-2024-12387 | Media (6.5) | 0.73% | — | 20 mar 2025 | A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and… |
| CVE-2024-11039 | Alta (8.8) | 2.1% | — | 20 mar 2025 | A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows attackers to achieve remote… |
| CVE-2024-11037 | Media (6.5) | 1.1% | — | 20 mar 2025 | A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing sensitive information such as… |
| CVE-2024-11033 | Media (6.5) | 0.73% | — | 20 mar 2025 | A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of form-data with a large filename in the file upload… |
| CVE-2024-11031 | Alta (7.5) | 0.65% | — | 20 mar 2025 | In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the… |
| CVE-2024-11030 | Alta (7.5) | 0.65% | — | 20 mar 2025 | GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper… |
| CVE-2024-10986 | Alta (8.8) | 0.82% | — | 20 mar 2025 | GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. Despite implementing protections… |
| CVE-2024-10956 | Alta (7.1) | 0.35% | — | 20 mar 2025 | GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the… |
| CVE-2024-10954 | Alta (8.8) | 1.5% | — | 20 mar 2025 | In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the… |
| CVE-2024-10950 | Alta (8.8) | 1.5% | — | 20 mar 2025 | In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause is the execution of user-provided prompts that generate untrusted… |
| CVE-2024-10948 | Media (6.5) | 0.84% | — | 20 mar 2025 | A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the… |
| CVE-2024-10819 | Alta (8.8) | 0.24% | — | 20 mar 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to… |
| CVE-2024-10812 | Media (6.1) | 0.58% | — | 20 mar 2025 | An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper… |
| CVE-2024-10714 | Alta (7.5) | 0.62% | — | 20 mar 2025 | A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the end of a multipart boundary during file upload. This results in the… |
| CVE-2025-25185 | Alta (7.5) | 0.64% | — | 3 mar 2025 | GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not properly account for soft links. An attacker can create a malicious file as a soft link pointing to a… |
| CVE-2024-10101 | Media (5.4) | 0.35% | — | 17 oct 2024 | A stored cross-site scripting (XSS) vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs at the /file endpoint, which renders HTML files. Malicious HTML files containing XSS payloads… |
| CVE-2024-10100 | Alta (7.5) | 0.62% | — | 17 oct 2024 | A path traversal vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of the file parameter, which is open to path traversal through URL encoding. This allows… |
| CVE-2024-31224 | Crítica (9.8) | 1.2% | — | 8 abr 2024 | GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from the client, which may risk… |
| CVE-2023-33979 | Media (6.5) | 0.73% | — | 31 may 2023 | gpt_academic provides a graphical interface for ChatGPT/GLM. A vulnerability was found in gpt_academic 3.37 and prior. This issue affects some unknown processing of the component Configuration File Handler. The… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.