CVE-2024-11039 is a critical pickle deserialization vulnerability affecting binary-husky/gpt_academic versions up to 3.83. This flaw allows authenticated attackers to achieve remote command execution by exploiting a deserialization whitelist that includes numpy, enabling the processing of malicious compressed packages. With a CVSS score of 8.8 (High), the vulnerability presents a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.91CPE matchmatch criteria | cpe:2.3:a:binary-husky:gpt_academic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.