TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-11037

N/A

Description

A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing sensitive information such as the OpenAI API key. This vulnerability is exploitable on Windows operating systems by accessing a specific URL that includes the absolute path of the project.

Details CVE

Score CVSS v3.1N/A
Publie3/20/2025
Derniere modification7/31/2025
Sourcenvd
Observations honeypot0

Produits affectes

binary-husky:gpt_academic

Faiblesses (CWE)

CWE-22

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.