Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-10956— Cross-Site WebSocket Hijacking in binary-husky/gpt_academic

EPSS 0.08% · P24
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-10956

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cross-Site WebSocket Hijacking in binary-husky/gpt_academic
Source: NVD (National Vulnerability Database)
Vulnerability Description
GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server, enabling unauthorized actions such as deleting conversation history without the victim's consent. The issue arises due to insufficient WebSocket authentication and lack of origin validation.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
源验证错误
Source: NVD (National Vulnerability Database)
Vulnerability Title
GPT Academic 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GPT Academic是binary-husky个人开发者的一个为 GPT/GLM 等 LLM 大语言模型提供实用化交互的接口。 GPT Academic 3.83版本存在访问控制错误漏洞,该漏洞源于跨站WebSocket劫持漏洞,可能导致未经授权的操作。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
binary-huskybinary-husky/gpt_academic unspecified ~ latest -

II. Public POCs for CVE-2024-10956

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-10956

登录查看更多情报信息。

Same Patch Batch · binary-husky · 2025-03-20 · 20 CVEs total

CVE-2024-11030SSRF in binary-husky/gpt_academic
CVE-2024-10948Arbitrary File Read via Upload Function in binary-husky/gpt_academic
CVE-2024-10714Denial of Service in binary-husky/gpt_academic
CVE-2024-10954Prompt Injection Leading to RCE in binary-husky/gpt_academic Plugin `manim`
CVE-2024-10812Open Redirect in binary-husky/gpt_academic
CVE-2024-10819CSRF to XSS in binary-husky/gpt_academic
CVE-2024-10950Code Injection in binary-husky/gpt_academic
CVE-2024-10986Local File Read (LFI) by Tarslip Symlink via arxiv_download() API in binary-husky/gpt_acad
CVE-2024-11039Deserialization of Untrusted Data in binary-husky/gpt_academic
CVE-2024-11033Denial of Service (DoS) in binary-husky/gpt_academic
CVE-2025-0183Stored XSS in binary-husky/gpt_academic
CVE-2024-11031SSRF in binary-husky/gpt_academic
CVE-2024-11037Path Traversal in binary-husky/gpt_academic
CVE-2024-12392Server-Side Request Forgery (SSRF) in binary-husky/gpt_academic
CVE-2024-12391Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic
CVE-2024-12387Improper Input Validation in binary-husky/gpt_academic
CVE-2024-12389Path Traversal in binary-husky/gpt_academic
CVE-2024-12388Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic
CVE-2024-12390Remote Code Execution in binary-husky/gpt_academic

IV. Related Vulnerabilities

V. Comments for CVE-2024-10956

No comments yet


Leave a comment