CVE-2024-10101

A stored cross-site scripting (XSS) vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs at the /file endpoint, which renders HTML files. Malicious HTML files containing XSS payloads can be uploaded and stored in the backend, leading to the execution of the payload in the victim's browser when the file is accessed. This can result in the theft of session cookies or other sensitive information.
CVSS

No CVSS.

References
Link Resource
https://huntr.com/bounties/0436d96a-a2c4-4ca5-9f3c-fd68eb74d2cb Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*

History

11 Jul 2025, 20:44

Type Values Removed Values Added
CPE cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*
References () https://huntr.com/bounties/0436d96a-a2c4-4ca5-9f3c-fd68eb74d2cb - () https://huntr.com/bounties/0436d96a-a2c4-4ca5-9f3c-fd68eb74d2cb - Exploit, Third Party Advisory
First Time Binary-husky
Binary-husky gpt Academic

17 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-17 19:15

Updated : 2025-07-11 20:44


NVD link : CVE-2024-10101

Mitre link : CVE-2024-10101


JSON object : View

Products Affected

binary-husky

  • gpt_academic
CWE

No CWE.