CVE-2024-10956
CVSS 3.0 Score 7.6 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 284
Summary
CVE-2024-10956 is a newly disclosed vulnerability affecting GPT Academy version 3.83, as detailed in the binary-husky/gpt_academic repository. This weakness permits Cross-Site WebSocket Hijacking (CSWSH), enabling attackers to seize control of existing WebSocket connections between users' browsers and the server. Unauthorized actions, such as deletion of conversation history, can be carried out without the victim's consent due to insufficient WebSocket authentication and lack of origin validation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.