We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exploit the vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.
Reserved 2024-11-08 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_aiCWE-918 Server-Side Request Forgery (SSRF)
huntr.com/bounties/729d9928-c28a-40fd-8a86-bb4ca2984bba
Support options