VYPR
High severity7.5NVD Advisory· Published Oct 17, 2024· Updated Jun 17, 2026

CVE-2024-10100

CVE-2024-10100

Description

A path traversal vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of the file parameter, which is open to path traversal through URL encoding. This allows attackers to view any file on the host system, including sensitive files such as critical application files, SSH keys, API keys, and configuration values.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*
    • (no CPE)range: =3.83
  • binary-husky/binary-husky/gpt_academicv5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.