CVE-2024-10948
Last modified
CVE-2024-10948 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the product. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the product. An attacker can exploit this vulnerability by intercepting the websocket request during file upload and replacing the file path with the path of the file they wish to read. The server then copies the file to the `private_upload` folder and provides the path to the copied file, which can be accessed via a GET request. This vulnerability can lead to the exposure of sensitive system files, potentially including credentials, configuration files, or sensitive user data.
Metrics
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Binary-Husky | Gpt Academic | 3.83 |
References
- https://huntr.com/bounties/290a379d-8441-4292-a553-3587e8c5c729Exploit, Third Party Advisory
- https://huntr.com/bounties/290a379d-8441-4292-a553-3587e8c5c729Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-10948?
How severe is CVE-2024-10948?
How do I fix CVE-2024-10948?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10942The All-in-One WP Migration and Backup plugin for WordPress …7.5
- CVE-2024-10943An authentication bypass vulnerability exists in the affecte…9.1
- CVE-2024-10944A Remote Code Execution vulnerability exists in the affected…8.4
- CVE-2024-10945A Local Privilege Escalation vulnerability exists in the aff…7.3
- CVE-2024-10946A vulnerability classified as critical has been found in Gua…7.2
- CVE-2024-10947A vulnerability classified as critical was found in Guangzho…7.2
- CVE-2024-1095The Build & Control Block Patterns – Boost up Gutenberg Edit…5.3
- CVE-2024-10950In binary-husky/gpt_academic version <= 3.83, the plugin `Co…8.8
- CVE-2024-10952The The Authors List plugin for WordPress is vulnerable to a…7.3
- CVE-2024-10953An authenticated data.all user is able to perform mutating U…5.3
- CVE-2024-10954In the `manim` plugin of binary-husky/gpt_academic, versions…8.8
- CVE-2024-10955A Regular Expression Denial of Service (ReDoS) vulnerability…6.5
Are you affected by CVE-2024-10948?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
