In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with 'http'. Attackers can exploit this vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00043}

epss

{'score': 0.00041}


Tue, 15 Jul 2025 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Mon, 14 Jul 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Binary-husky
Binary-husky gpt Academic
Weaknesses CWE-918
CPEs cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*
Vendors & Products Binary-husky
Binary-husky gpt Academic
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with 'http'. Attackers can exploit this vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.
Title SSRF in binary-husky/gpt_academic
Weaknesses CWE-200
References
Metrics cvssV3_0

{'score': 7.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:09:16.417Z

Updated: 2025-07-15T10:48:56.680Z

Reserved: 2024-11-08T21:31:03.471Z

Link: CVE-2024-11031

cve-icon Vulnrichment

Updated: 2025-03-20T17:51:26.874Z

cve-icon NVD

Status : Modified

Published: 2025-03-20T10:15:22.820

Modified: 2025-07-15T11:15:23.983

Link: CVE-2024-11031

cve-icon Redhat

No data.