Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-12388— Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic

EPSS 0.47% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-12388

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user input, which can take polynomial time to match certain crafted inputs. This allows an attacker to send a small malicious payload to the server, causing it to become unresponsive and unable to handle any requests from other users.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
CWE-1333
Source: NVD (National Vulnerability Database)
Vulnerability Title
GPT Academic 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GPT Academic是binary-husky个人开发者的一个为 GPT/GLM 等 LLM 大语言模型提供实用化交互的接口。 GPT Academic 310122f版本存在安全漏洞,该漏洞源于正则表达式使用不当,可能导致正则表达式拒绝服务攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
binary-huskybinary-husky/gpt_academic unspecified ~ latest -

II. Public POCs for CVE-2024-12388

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-12388

登录查看更多情报信息。

Same Patch Batch · binary-husky · 2025-03-20 · 20 CVEs total

CVE-2024-11033Denial of Service (DoS) in binary-husky/gpt_academic
CVE-2024-10948Arbitrary File Read via Upload Function in binary-husky/gpt_academic
CVE-2024-10714Denial of Service in binary-husky/gpt_academic
CVE-2024-10954Prompt Injection Leading to RCE in binary-husky/gpt_academic Plugin `manim`
CVE-2024-10812Open Redirect in binary-husky/gpt_academic
CVE-2024-10819CSRF to XSS in binary-husky/gpt_academic
CVE-2024-10956Cross-Site WebSocket Hijacking in binary-husky/gpt_academic
CVE-2024-10950Code Injection in binary-husky/gpt_academic
CVE-2024-10986Local File Read (LFI) by Tarslip Symlink via arxiv_download() API in binary-husky/gpt_acad
CVE-2024-11039Deserialization of Untrusted Data in binary-husky/gpt_academic
CVE-2025-0183Stored XSS in binary-husky/gpt_academic
CVE-2024-11030SSRF in binary-husky/gpt_academic
CVE-2024-11031SSRF in binary-husky/gpt_academic
CVE-2024-11037Path Traversal in binary-husky/gpt_academic
CVE-2024-12392Server-Side Request Forgery (SSRF) in binary-husky/gpt_academic
CVE-2024-12391Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic
CVE-2024-12387Improper Input Validation in binary-husky/gpt_academic
CVE-2024-12389Path Traversal in binary-husky/gpt_academic
CVE-2024-12390Remote Code Execution in binary-husky/gpt_academic

IV. Related Vulnerabilities

V. Comments for CVE-2024-12388

No comments yet


Leave a comment