CVE-2024-10100 is a high-severity path traversal vulnerability (CVSS 7.5) affecting binary-husky/gpt_academic version 3.83. This flaw allows unauthenticated attackers to view any file on the host system, including sensitive data like SSH keys and configuration files, due to improper handling of URL-encoded file parameters. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion, the potential for unauthorized information disclosure is significant. There is no evidence of active exploitation, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.83CPE matchmatch criteria | cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.