CVE-2024-10950: Binary-Husky Gpt Academic
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause is the execution of user-provided prompts that generate untrusted code without a sandbox, allowing the execution of parts of the LLM-generated code. This vulnerability can be exploited by an attacker to achieve remote code execution (RCE) on the application backend server, potentially gaining full control of the server.
Affected products
- Binary-Husky Gpt Academic: up to and including 3.83
Published 2025-03-20. Last modified 2026-06-17.