High severity8.8NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-10954
CVE-2024-10954
Description
In the manim plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. This allows an attacker to perform remote code execution (RCE) on the app backend server by injecting malicious code through the prompt.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:binary-husky:gpt_academic:-:*:*:*:*:*:*:*
- binary-husky/binary-husky/gpt_academicv5Range: unspecified
Patches
Vulnerability mechanics
References
1- huntr.com/bounties/72d034e3-6ca2-495d-98a7-ac9565588c09nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.