CVE-2024-11030

CVSS 3.0 Score 7.7 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 918

Summary

CVE-2024-11030 is a Server-Side Request Forgery (SSRF) vulnerability affecting GPT Academic version 3.83. The issue arises from the HotReload plugin function, which utilizes the API call crazy_utils.get_files_from_everything() without appropriate sanitization. This weakness enables attackers to manipulate the request and abuse the victim's Gradio Web server credentials, allowing unauthorized access to web resources.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share