CVE-2024-12390

CVSS 3.0 Score 8.8 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 475

Summary

CVE-2024-12390 is a newly disclosed vulnerability affecting the gpt_academic version of binary-husky's Git repository. The issue arises due to insufficient validation of user-supplied RAR files, which can be exploited using the Python rarfile module. This module, which supports symlinks, can be manipulated to execute arbitrary file writes. An attacker can potentially exploit this vulnerability to write malicious code into sensitive files, including SSH keys, crontab files, or even the application's own source code, leading to remote code execution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share