PT-2025-12087 · Unknown · Gpt Academic

CVE-2024-10986

·

Published

2025-03-20

·

Updated

2025-07-14

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPT Academic version 3.83
Description The issue concerns a Local File Read (LFI) vulnerability through the HotReload function, which can download and extract tar.gz files from arxiv.org. Despite protections against path traversal, the application is vulnerable due to its handling of symlinks, specifically the Tarslip triggered by them, allowing attackers to read arbitrary local files from the victim server.
Recommendations For GPT Academic version 3.83, as a temporary workaround, consider disabling the HotReload function until a patch is available. Restrict access to the HotReload function to minimize the risk of exploitation. Avoid using the HotReload function to download and extract tar.gz files from untrusted sources until the issue is resolved.

Exploit

Fix

RCE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10986

Affected Products

Gpt Academic