PT-2025-12082 · Unknown · Binary-Husky/Gpt Academic

CVE-2024-10948

·

Published

2025-03-20

·

Updated

2025-07-29

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions binary-husky/gpt academic (affected versions not specified)
Description A vulnerability in the upload function allows any user to read arbitrary files on the system, including sensitive files such as config.py. An attacker can exploit this issue by intercepting the websocket request during file upload and replacing the file path with the path of the file they wish to read. The server then copies the file to the private upload folder and provides the path to the copied file, which can be accessed via a GET request. This can lead to the exposure of sensitive system files, potentially including credentials, configuration files, or sensitive user data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10948

Affected Products

Binary-Husky/Gpt Academic