Security Advisory

CVE-2025-0183

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-20 10:10:24
Last updated 2025-03-20 18:21:58
Assigner @huntr_ai
State PUBLISHED

Description

A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inject malicious scripts into the `debug_log.html` file generated by the module. When an admin visits this debug report, the injected scripts can execute, potentially leading to unauthorized actions and data access.