High severity8.8NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-12390
CVE-2024-12390
Description
A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The Python rarfile module, which supports symlinks, can be exploited to perform arbitrary file writes. This can lead to remote code execution by writing to sensitive files such as SSH keys, crontab files, or the application's own code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:binary-husky:gpt_academic:2024-10-15:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:binary-husky:gpt_academic:2024-10-15:*:*:*:*:*:*:*
- (no CPE)range: git 310122f
- binary-husky/binary-husky/gpt_academicv5Range: unspecified
Patches
Vulnerability mechanics
References
1- huntr.com/bounties/1add2b26-460d-4aa5-8fda-ab045d153177nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.