VYPR

papersgpt-for-zotero

by Papersgpt

CVEs (1)

  • CVE-2026-73032CriAug 11, 2026
    risk 0.55cvss 9.6epss

    PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt…