Vulnerability Description
A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing sensitive information such as the OpenAI API key. This vulnerability is exploitable on Windows operating systems by accessing a specific URL that includes the absolute path of the project.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Binary-Husky | Gpt Academic | 2024-10-10 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/91243fc1-f287-4f4b-8aa6-dfe3efff23e5ExploitThird Party Advisory
FAQ
What is CVE-2024-11037?
CVE-2024-11037 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing sensitive i...
How severe is CVE-2024-11037?
CVE-2024-11037 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-11037?
Check the references section above for vendor advisories and patch information. Affected products include: Binary-Husky Gpt Academic.