← Back

CVE-2024-10101

nvd nist
Published: Oct 17, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: security@huntr.dev (Secondary)

Description

A stored cross-site scripting (XSS) vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs at the /file endpoint, which renders HTML files. Malicious HTML files containing XSS payloads can be uploaded and stored in the backend, leading to the execution of the payload in the victim's browser when the file is accessed. This can result in the theft of session cookies or other sensitive information.

Affected (1)

1 product
Gpt Academic
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.83

References (1)

Source: security@huntr.dev
ExploitThird Party Advisory

Timeline

No history available yet.