{"id":"CVE-2024-11030","summary":"SSRF in binary-husky/gpt_academic","details":"GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exploit the vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.","modified":"2026-08-12T03:51:44.734459606Z","published":"2025-03-20T10:11:15.720Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11030.json","cna_assigner":"@huntr_ai","cwe_ids":["CWE-918"]},"references":[{"type":"WEB","url":"https://huntr.com/bounties/729d9928-c28a-40fd-8a86-bb4ca2984bba"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11030.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-11030"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/binary-husky/gpt_academic","events":[{"introduced":"573dc4d1844705b738d3c830774c4d10dca96fad"},{"last_affected":"573dc4d1844705b738d3c830774c4d10dca96fad"}],"database_specific":{"cpe":"cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.83"},{"last_affected":"3.83"}],"source":"CPE_STRING"}}],"versions":["3.83","version3.83"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11030.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}