PT-2025-12084 · Unknown+1 · Binary-Husky/Gpt Academic+1

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2024-10954

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions binary-husky/gpt academic versions prior to the fix
Description A vulnerability exists due to improper handling of user-provided prompts in the manim plugin. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox, allowing an attacker to perform remote code execution (RCE) on the app backend server by injecting malicious code through the prompt.
Recommendations For versions prior to the fix, consider disabling the manim plugin until a patch is available to prevent remote code execution. Restrict access to the app backend server to minimize the risk of exploitation. Avoid using the manim plugin with untrusted user-provided prompts until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10954

Affected Products

Binary-Husky/Gpt Academic
Manim