PT-2025-12084 · Unknown+1 · Binary-Husky/Gpt Academic+1
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-10954
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
binary-husky/gpt academic versions prior to the fix
Description
A vulnerability exists due to improper handling of user-provided prompts in the
manim plugin. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox, allowing an attacker to perform remote code execution (RCE) on the app backend server by injecting malicious code through the prompt.Recommendations
For versions prior to the fix, consider disabling the
manim plugin until a patch is available to prevent remote code execution. Restrict access to the app backend server to minimize the risk of exploitation. Avoid using the manim plugin with untrusted user-provided prompts until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Code Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Binary-Husky/Gpt Academic
Manim