A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, which can lead to an out-of-memory crash. This issue arises due to improper input validation when handling compressed file uploads.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, which can lead to an out-of-memory crash. This issue arises due to improper input validation when handling compressed file uploads. | |
Title | Improper Input Validation in binary-husky/gpt_academic | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:21.371Z
Updated: 2025-03-20T13:06:27.128Z
Reserved: 2024-12-09T21:00:36.453Z
Link: CVE-2024-12387

Updated: 2025-03-20T13:06:17.969Z

Status : Received
Published: 2025-03-20T10:15:28.010
Modified: 2025-03-20T13:15:35.803
Link: CVE-2024-12387

No data.