CVE-2024-12392

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
20/03/2025
Last modified:
31/07/2025

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vulnerability to make the application access any URL, including internal services, and read the response. This can be used to access data that are only accessible from the server, such as AWS metadata credentials, and can escalate local exploits to network-based attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:binary-husky:gpt_academic:2024-10-15:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools