VYPR
Unrated severityOSV Advisory· Published Jan 23, 2026· Updated Jan 23, 2026

GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability

CVE-2026-0762

Description

GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Interaction with a malicious DAAS server is required to exploit this vulnerability but attack vectors may vary depending on the implementation.

The specific flaw exists within the stream_daas function. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27956.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • version2.68-3, version2.68-4, version2.7, …+ 1 more
    • (no CPE)range: version2.68-3, version2.68-4, version2.7, …
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.