CVE-2024-10954 Information
Mar 21, 2025
cve
Description
In the manim plugin of binary-husky/gpt_academic versions prior to the fix a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. This allows an attacker to perform remote code execution (RCE) on the app backend server by injecting malicious code through the prompt.
Reference
https://huntr.com/bounties/72d034e3-6ca2-495d-98a7-ac9565588c09
Share on: