Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-31224

Опубликовано: 08 апр. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from the client, which may risk remote code execution. Any device that exposes the GPT Academic service to the Internet is vulnerable. Version 3.74 contains a patch for the issue. There are no known workarounds aside from upgrading to a patched version.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:binary-husky:gpt_academic:*:*:*:*:*:*:*:*
Версия от 3.64-1 (включая) до 3.74 (исключая)

EPSS

Процентиль: 90%
0.05825
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

EPSS

Процентиль: 90%
0.05825
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502