Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-10986

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. Despite implementing protections against path traversal, the application overlooks the Tarslip triggered by symlinks. This oversight allows attackers to read arbitrary local files from the victim server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00188
Низкий

8.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 8.8
github
11 месяцев назад

GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. Despite implementing protections against path traversal, the application overlooks the Tarslip triggered by symlinks. This oversight allows attackers to read arbitrary local files from the victim server.

EPSS

Процентиль: 41%
0.00188
Низкий

8.8 High

CVSS3

Дефекты

CWE-59