File Exposure Vulnerability in Binary-Husky GPT Academic Plugin
CVE-2024-10948
What is CVE-2024-10948?
A security issue in the upload function of Binary-Husky's gpt_academic enables any user to read arbitrary files on the system, including sensitive files like config.py. By intercepting a websocket request during a file upload, an attacker can manipulate the file path to access files they shouldn't be able to. The server facilitates this exploitation by copying the file to a designated folder and exposing the copied file path through a GET request. This flaw poses a significant risk, as it can lead to unauthorized access to sensitive system files, potentially revealing credentials and critical configuration data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
binary-husky/gpt_academic <= unspecified
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
