Impact
PapersGPT for Zotero 0.6.1 contains an unsanitized eval of JavaScript returned from an LLM endpoint, which permits an attacker to inject executable code. This flaw is identified as CWE-94 and results in remote code execution in Zotero’s chrome‑privileged context, enabling file read/write, process execution, and full access to all Zotero data.
Affected Systems
The vulnerability affects the PapersGPT for Zotero extension version 0.6.1 distributed by the papersgpt vendor. No other versions are listed as vulnerable in the CVE data.
Risk and Exploitability
The flaw carries a CVSS score of 9.4, classified as critical. The EPSS score is less than 1%, indicating a currently low exploitation probability, and the issue is not listed in CISA KEV. Attackers can exploit the vulnerability through prompt injection in PDFs, man‑in‑the‑middle interception of API requests, or by using a malicious custom LLM endpoint, all of which would enable code execution within Zotero’s privileged environment.
OpenCVE Enrichment