Server-Side Request Forgery Vulnerability in GPT Academic by Binary Husky
CVE-2024-11031
What is CVE-2024-11031?
In version 3.83 of gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability has been identified within the Markdown_Translate.get_files_from_everything() API. This issue arises from the HotReload plugin functionality, which inadequately validates URLs, permitting attackers to access arbitrary web hosts simply by ensuring that URLs start with 'http'. By exploiting this flaw, attackers may leverage the Gradio Web server credentials associated with the victim's GPT Academic instance, gaining unauthorized access to sensitive resources across the web.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
binary-husky/gpt_academic <= unspecified
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
