GPT Academic是binary-husky个人开发者的一个为 GPT/GLM 等 LLM 大语言模型提供实用化交互的接口。 GPT Academic 3.83版本存在输入验证错误漏洞,该漏洞源于用户重定向到用户控制的file参数指定的URL时未进行适当的验证或清理,可能导致钓鱼攻击、恶意软件分发和用户凭据窃取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| binary-husky | binary-husky/gpt_academic | unspecified ~ latest | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An open redirect vulnerability exists in GPT Academic v1.3.9, where the file parameter in the /file= endpoint can be manipulated to redirect users to malicious websites. This could facilitate phishing attacks by tricking users into visiting attacker-controlled URLs. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-10812.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-11030 | SSRF in binary-husky/gpt_academic | |
| CVE-2024-10948 | Arbitrary File Read via Upload Function in binary-husky/gpt_academic | |
| CVE-2024-10714 | Denial of Service in binary-husky/gpt_academic | |
| CVE-2024-10954 | Prompt Injection Leading to RCE in binary-husky/gpt_academic Plugin `manim` | |
| CVE-2024-10819 | CSRF to XSS in binary-husky/gpt_academic | |
| CVE-2024-10956 | Cross-Site WebSocket Hijacking in binary-husky/gpt_academic | |
| CVE-2024-10950 | Code Injection in binary-husky/gpt_academic | |
| CVE-2024-10986 | Local File Read (LFI) by Tarslip Symlink via arxiv_download() API in binary-husky/gpt_acad | |
| CVE-2024-11039 | Deserialization of Untrusted Data in binary-husky/gpt_academic | |
| CVE-2024-11033 | Denial of Service (DoS) in binary-husky/gpt_academic | |
| CVE-2025-0183 | Stored XSS in binary-husky/gpt_academic | |
| CVE-2024-11031 | SSRF in binary-husky/gpt_academic | |
| CVE-2024-11037 | Path Traversal in binary-husky/gpt_academic | |
| CVE-2024-12392 | Server-Side Request Forgery (SSRF) in binary-husky/gpt_academic | |
| CVE-2024-12391 | Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic | |
| CVE-2024-12387 | Improper Input Validation in binary-husky/gpt_academic | |
| CVE-2024-12389 | Path Traversal in binary-husky/gpt_academic | |
| CVE-2024-12388 | Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic | |
| CVE-2024-12390 | Remote Code Execution in binary-husky/gpt_academic |
No comments yet