Server-Side Request Forgery Vulnerability in GPT Academic by Binary Husky
CVE-2024-11031
7.5HIGH
What is CVE-2024-11031?
In version 3.83 of gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability has been identified within the Markdown_Translate.get_files_from_everything() API. This issue arises from the HotReload plugin functionality, which inadequately validates URLs, permitting attackers to access arbitrary web hosts simply by ensuring that URLs start with 'http'. By exploiting this flaw, attackers may leverage the Gradio Web server credentials associated with the victim's GPT Academic instance, gaining unauthorized access to sensitive resources across the web.
Affected Version(s)
binary-husky/gpt_academic <= unspecified
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved