CVE-2025-0183

A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inject malicious scripts into the `debug_log.html` file generated by the module. When an admin visits this debug report, the injected scripts can execute, potentially leading to unauthorized actions and data access.
CVSS

No CVSS.

References
Link Resource
https://huntr.com/bounties/53bced90-64a9-4ca2-8f2f-282c4ce84d1f Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:binary-husky:gpt_academic:3.90:*:*:*:*:*:*:*

History

01 Aug 2025, 01:53

Type Values Removed Values Added
CPE cpe:2.3:a:binary-husky:gpt_academic:3.90:*:*:*:*:*:*:*
References () https://huntr.com/bounties/53bced90-64a9-4ca2-8f2f-282c4ce84d1f - () https://huntr.com/bounties/53bced90-64a9-4ca2-8f2f-282c4ce84d1f - Exploit, Third Party Advisory
First Time Binary-husky
Binary-husky gpt Academic

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-08-01 01:53


NVD link : CVE-2025-0183

Mitre link : CVE-2025-0183


JSON object : View

Products Affected

binary-husky

  • gpt_academic
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')