Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-12390— Remote Code Execution in binary-husky/gpt_academic

EPSS 2.91% · P86
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-12390

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Remote Code Execution in binary-husky/gpt_academic
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The Python rarfile module, which supports symlinks, can be exploited to perform arbitrary file writes. This can lead to remote code execution by writing to sensitive files such as SSH keys, crontab files, or the application's own code.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: NVD (National Vulnerability Database)
Vulnerability Title
GPT Academic 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GPT Academic是binary-husky个人开发者的一个为 GPT/GLM 等 LLM 大语言模型提供实用化交互的接口。 GPT Academic存在安全漏洞,该漏洞源于未正确验证用户提供的RAR文件,可能导致远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
binary-huskybinary-husky/gpt_academic unspecified ~ latest -

II. Public POCs for CVE-2024-12390

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-12390

登录查看更多情报信息。

Same Patch Batch · binary-husky · 2025-03-20 · 20 CVEs total

CVE-2024-11033Denial of Service (DoS) in binary-husky/gpt_academic
CVE-2024-10948Arbitrary File Read via Upload Function in binary-husky/gpt_academic
CVE-2024-10714Denial of Service in binary-husky/gpt_academic
CVE-2024-10954Prompt Injection Leading to RCE in binary-husky/gpt_academic Plugin `manim`
CVE-2024-10812Open Redirect in binary-husky/gpt_academic
CVE-2024-10819CSRF to XSS in binary-husky/gpt_academic
CVE-2024-10956Cross-Site WebSocket Hijacking in binary-husky/gpt_academic
CVE-2024-10950Code Injection in binary-husky/gpt_academic
CVE-2024-10986Local File Read (LFI) by Tarslip Symlink via arxiv_download() API in binary-husky/gpt_acad
CVE-2024-11039Deserialization of Untrusted Data in binary-husky/gpt_academic
CVE-2025-0183Stored XSS in binary-husky/gpt_academic
CVE-2024-11030SSRF in binary-husky/gpt_academic
CVE-2024-11031SSRF in binary-husky/gpt_academic
CVE-2024-11037Path Traversal in binary-husky/gpt_academic
CVE-2024-12392Server-Side Request Forgery (SSRF) in binary-husky/gpt_academic
CVE-2024-12391Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic
CVE-2024-12387Improper Input Validation in binary-husky/gpt_academic
CVE-2024-12389Path Traversal in binary-husky/gpt_academic
CVE-2024-12388Regular Expression Denial of Service (ReDoS) in binary-husky/gpt_academic

IV. Related Vulnerabilities

V. Comments for CVE-2024-12390

No comments yet


Leave a comment