PT-2025-12088 · Unknown+2 · Gpt Academic+2

Published

2025-03-20

·

Updated

2025-07-14

·

CVE-2024-11030

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GPT Academic version 3.83
Description The issue is related to a Server-Side Request Forgery (SSRF) vulnerability. It occurs through the HotReload plugin function, which calls the crazy utils.get files from everything() API without proper sanitization. This allows attackers to exploit the vulnerability and abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.
Recommendations For GPT Academic version 3.83, consider disabling the HotReload plugin function until a patch is available to prevent exploitation of the SSRF vulnerability. Restrict access to the crazy utils.get files from everything() API to minimize the risk of unauthorized web resource access.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-11030

Affected Products

Gpt Academic
Gradio
Hotreload