CVE-2024-10954

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
20/03/2025
Last modified:
15/10/2025

Description

In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. This allows an attacker to perform remote code execution (RCE) on the app backend server by injecting malicious code through the prompt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:binary-husky:gpt_academic:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools