Security Advisory

CVE-2024-10950

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-03-20 10:10:36
Last updated 2025-10-15 12:50:14
Assigner @huntr_ai
CVSS score 8.8
State PUBLISHED

Description

In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause is the execution of user-provided prompts that generate untrusted code without a sandbox, allowing the execution of parts of the LLM-generated code. This vulnerability can be exploited by an attacker to achieve remote code execution (RCE) on the application backend server, potentially gaining full control of the server.