Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7055 | GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exploit the vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources. |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Binary-husky
Binary-husky gpt Academic |
|
| CPEs | cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:* | |
| Vendors & Products |
Binary-husky
Binary-husky gpt Academic |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exploit the vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources. | |
| Title | SSRF in binary-husky/gpt_academic | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T13:24:02.898Z
Reserved: 2024-11-08T21:07:52.331Z
Link: CVE-2024-11030
Updated: 2025-03-20T13:23:53.184Z
Status : Analyzed
Published: 2025-03-20T10:15:22.707
Modified: 2025-07-14T16:40:31.410
Link: CVE-2024-11030
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:22:19Z
EUVD