The specific flaw exists within the stream_daas function. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27956.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-26-028/ |
|
Wed, 18 Feb 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Binary-husky
Binary-husky gpt Academic |
|
| CPEs | cpe:2.3:a:binary-husky:gpt_academic:3.91:*:*:*:*:*:*:* | |
| Vendors & Products |
Binary-husky
Binary-husky gpt Academic |
Fri, 23 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gpt Academic Project
Gpt Academic Project gpt Academic |
|
| Vendors & Products |
Gpt Academic Project
Gpt Academic Project gpt Academic |
Fri, 23 Jan 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Interaction with a malicious DAAS server is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the stream_daas function. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27956. | |
| Title | GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2026-01-23T19:23:27.751Z
Reserved: 2026-01-08T22:49:51.276Z
Link: CVE-2026-0762
Updated: 2026-01-23T19:23:23.173Z
Status : Analyzed
Published: 2026-01-23T04:16:02.973
Modified: 2026-02-18T16:41:56.887
Link: CVE-2026-0762
No data.
OpenCVE Enrichment
Updated: 2026-04-18T03:30:25Z