PT-2025-12089 · Unknown+2 · Binary-Husky/Gpt Academic+2

Published

2025-03-20

·

Updated

2025-07-15

·

CVE-2024-11031

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions binary-husky/gpt academic version 3.83
Description A Server-Side Request Forgery (SSRF) issue exists in the Markdown Translate.get files from everything() API, allowing attackers to download arbitrary web hosts by exploiting the HotReload plugin function. This function only checks if the link starts with 'http', enabling abuse of the victim GPT Academic's Gradio Web server credentials to access unauthorized web resources.
Recommendations For version 3.83, consider disabling the HotReload plugin function or restricting its use to prevent exploitation until a patch is available. Additionally, restrict access to the Markdown Translate.get files from everything() API to minimize the risk of unauthorized web resource access.

Exploit

Fix

Information Disclosure

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-11031

Affected Products

Gradio
Hotreload
Binary-Husky/Gpt Academic