CVE-2024-11037
CVSS 3.0 Score 6.5 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 22
Summary
CVE-2024-11037 is a newly disclosed path traversal vulnerability affecting the gpt_academic project in the binary-husky repository. The issue, occurring at commit 679352d, permits an attacker to bypass the blocked_paths security measure and access the sensitive config.py file. Containing an OpenAI API key, this file poses a significant risk if accessed by unauthorized entities. This vulnerability is exploitable through a specific URL on Windows operating systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.