CVE-2024-10956
Last modified
CVE-2024-10956 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server, enabling unauthorized actions such as deleting conversation history without the victim's consent. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server, enabling unauthorized actions such as deleting conversation history without the victim's consent. The issue arises due to insufficient WebSocket authentication and lack of origin validation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Binary-Husky | Gpt Academic | 3.83 |
References
- https://huntr.com/bounties/0f8403ad-5f60-4eb9-9f51-8fbd2e41eda4Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-10956?
How severe is CVE-2024-10956?
How do I fix CVE-2024-10956?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-1095The Build & Control Block Patterns – Boost up Gutenberg Edit…5.3
- CVE-2024-10950In binary-husky/gpt_academic version <= 3.83, the plugin `Co…8.8
- CVE-2024-10952The The Authors List plugin for WordPress is vulnerable to a…7.3
- CVE-2024-10953An authenticated data.all user is able to perform mutating U…5.3
- CVE-2024-10954In the `manim` plugin of binary-husky/gpt_academic, versions…8.8
- CVE-2024-10955A Regular Expression Denial of Service (ReDoS) vulnerability…6.5
- CVE-2024-10957The UpdraftPlus: WP Backup & Migration Plugin plugin for Wor…8.8
- CVE-2024-10958The The WP Photo Album Plus plugin for WordPress is vulnerab…7.3
- CVE-2024-10959The The Active Products Tables for WooCommerce. Use construc…7.3
- CVE-2024-1096Twister Antivirus v8.17 is vulnerable to a Denial of Service…5.5
- CVE-2024-10960The Brizy – Page Builder plugin for WordPress is vulnerable …8.8
- CVE-2024-10961The Social Login plugin for WordPress is vulnerable to authe…9.8
Are you affected by CVE-2024-10956?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
