Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-33574 | A stored cross-site scripting (XSS) vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs at the /file endpoint, which renders HTML files. Malicious HTML files containing XSS payloads can be uploaded and stored in the backend, leading to the execution of the payload in the victim's browser when the file is accessed. This can result in the theft of session cookies or other sensitive information. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Fri, 11 Jul 2025 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:* | 
Fri, 20 Dec 2024 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        cvssV3_0
         
  | 
    
        
        
        cvssV3_0
         
  | 
Mon, 04 Nov 2024 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        cvssV3_0
         
  | 
    
        
        
        cvssV3_0
         
  | 
Thu, 17 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Binary-husky
         Binary-husky gpt Academic  | 
|
| CPEs | cpe:2.3:a:binary-husky:gpt_academic:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Binary-husky
         Binary-husky gpt Academic  | 
|
| Metrics | 
        
        ssvc
         
  | 
Thu, 17 Oct 2024 18:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs at the /file endpoint, which renders HTML files. Malicious HTML files containing XSS payloads can be uploaded and stored in the backend, leading to the execution of the payload in the victim's browser when the file is accessed. This can result in the theft of session cookies or other sensitive information. | |
| Title | Stored XSS in binary-husky/gpt_academic | |
| Weaknesses | CWE-79 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_0
         
  | 
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-12-20T20:53:16.445Z
Reserved: 2024-10-17T17:38:16.094Z
Link: CVE-2024-10101
Updated: 2024-10-17T19:24:16.844Z
Status : Analyzed
Published: 2024-10-17T19:15:21.713
Modified: 2025-07-11T20:44:32.730
Link: CVE-2024-10101
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD