Binary Husky maintains a focused academic research tool, GPT Academic, that despite a narrow product footprint has achieved prominence in the vulnerability landscape, likely due to its integration into research and educational deployments. The vendor's disclosures span a range of input-handling and integration vulnerabilities that reflect the product's role as an interface to large language models and third-party APIs. Defenders deploying this tool should treat advisories as part of their broader supply-chain monitoring, particularly where GPT Academic sits between user-controlled input and external model endpoints; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Binary Husky over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-0764CRITICAL GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Jan 23, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-0763CRITICAL GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c | Jan 23, 2026 | 9.8 | 30 | NO | NO |
CVE-2024-10812MEDIUM An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in t | Mar 20, 2025 | 6.1 | 27 | NO | YES |
CVE-2024-31224CRITICAL GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy | Apr 8, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-0762HIGH GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins | Jan 23, 2026 | 8.1 | 25 | NO | NO |
CVE-2025-10236HIGH A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the comp | Sep 11, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-12390HIGH A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper | Mar 20, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-12389HIGH A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation. | Mar 20, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-11039HIGH A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerabil | Mar 20, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-10986HIGH GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. | Mar 20, 2025 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Binary Husky.
Media articles that mention a CVE ID that affects a product developed by Binary Husky — matched by CVE ID, not by vendor name.