Skip to main content

Vendor/product archive

binary-husky / gpt_academic CVEs

Beta · best-effort

29 CVEs tagged to binary-husky / gpt_academic3 Critical, 14 High, 11 Medium, 1 Low, 0 Unrated.

CVE-2026-0764

Published Jan 23, 2026

GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0763

Published Jan 23, 2026

GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0762

Published Jan 23, 2026

GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10236

Published Sep 11, 2025

A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the com…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-0183

Published Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inj…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-12392

Published Mar 20, 2025

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12391

Published Mar 20, 2025

A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (ReDoS) attack. The function '解析项目源码(手动指定和筛选源码文件类型)' permits…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12390

Published Mar 20, 2025

A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without prope…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12389

Published Mar 20, 2025

A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12388

Published Mar 20, 2025

A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12387

Published Mar 20, 2025

A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11039

Published Mar 20, 2025

A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerabi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11037

Published Mar 20, 2025

A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11033

Published Mar 20, 2025

A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of form-data wit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11031

Published Mar 20, 2025

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11030

Published Mar 20, 2025

GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_eve…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10986

Published Mar 20, 2025

GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10956

Published Mar 20, 2025

GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an ex…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10954

Published Mar 20, 2025

In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the exec…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10950

Published Mar 20, 2025

In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause is the execution of user-prov…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10948

Published Mar 20, 2025

A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10819

Published Mar 20, 2025

A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, explo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10812

Published Mar 20, 2025

An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10714

Published Mar 20, 2025

A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the end of a multipart boundary d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25185

Published Mar 3, 2025

GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not properly account for soft links. An attacker can create a malici…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 29 CVEsPage 1 of 2