CVE-2024-11031

Publication date

2025-03-20 10:09:16

Family

@huntr_ai

State

PUBLISHED

Description

In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with http. Attackers can exploit this vulnerability to abuse the victim GPT Academics Gradio Web servers credentials to access unauthorized web resources.