Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11039

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows attackers to achieve remote command execution by deserializing untrusted data. The issue arises from the inclusion of numpy in the deserialization whitelist, which can be exploited by constructing a malicious compressed package containing a merge_result.pkl file and a merge_proofread_en.tex file. The vulnerability is fixed in commit 91f5e6b.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:binary-husky:gpt_academic:*:*:*:*:*:*:*:*
Версия до 3.91 (исключая)

EPSS

Процентиль: 66%
0.00526
Низкий

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
github
11 месяцев назад

A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows attackers to achieve remote command execution by deserializing untrusted data. The issue arises from the inclusion of numpy in the deserialization whitelist, which can be exploited by constructing a malicious compressed package containing a merge_result.pkl file and a merge_proofread_en.tex file. The vulnerability is fixed in commit 91f5e6b.

CVSS3: 8.8
fstec
больше 1 года назад

Уязвимость модуля latex_pickle_io.py приложения машинного обучения GPT Academic, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 66%
0.00526
Низкий

8.8 High

CVSS3

Дефекты

CWE-502