CVE-2024-10956

CVSS 3.0 Score 7.6 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 284

Summary

CVE-2024-10956 is a newly disclosed vulnerability affecting GPT Academy version 3.83, as detailed in the binary-husky/gpt_academic repository. This weakness permits Cross-Site WebSocket Hijacking (CSWSH), enabling attackers to seize control of existing WebSocket connections between users' browsers and the server. Unauthorized actions, such as deletion of conversation history, can be carried out without the victim's consent due to insufficient WebSocket authentication and lack of origin validation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share