CVE-2024-11039
CVSS 3.0 Score 8.8 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 502
Summary
CVE-2024-11039 is a pickle deserialization vulnerability affecting the Latex English error correction plug-in of binary-husky's gpt_academic, versions 3.83 and below. This issue enables remote command execution by allowing attackers to deserialize untrusted data. The root cause stems from the inclusion of numpy in the deserialization whitelist. An exploit involves creating a malicious compressed package containing a merge_result.pkl file and a merge_proofread_en.tex file. The vulnerability has been rectified through commit 91f5e6b.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.