Security Advisory

CVE-2024-10954

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-20 10:10:46
Last updated 2025-10-15 12:49:27
Assigner @huntr_ai
State PUBLISHED

Description

In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. This allows an attacker to perform remote code execution (RCE) on the app backend server by injecting malicious code through the prompt.