CVE-2024-12392

MEDIUM

binary-husky gpt_academic - Server-Side Request Forgery via Arxiv Paper Download URL

Title source: llm
STIX 2.1

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vulnerability to make the application access any URL, including internal services, and read the response. This can be used to access data that are only accessible from the server, such as AWS metadata credentials, and can escalate local exploits to network-based attacks.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0056
EPSS Percentile 42.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-918
Status published
Products (1)
binary-husky/gpt_academic 2024-10-15
Published Mar 20, 2025
Tracked Since Feb 18, 2026