CVE-2025-10236 (CNNVD-202509-1727)
中文标题:
GPT Academic 路径遍历漏洞
英文标题:
binary-husky gpt_academic LaTeX File latex_toolbox.py merge_tex_files_ path traversal
漏洞描述
中文描述:
GPT Academic是binary-husky个人开发者的一个为 GPT/GLM 等 LLM 大语言模型提供实用化交互的接口。 GPT Academic 3.91及之前版本存在路径遍历漏洞,该漏洞源于对文件crazy_functions/latex_fns/latex_toolbox.py中参数input的错误操作,可能导致路径遍历攻击。
英文描述:
A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the component LaTeX File Handler. Such manipulation of the argument \input{} leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| binary-husky | gpt_academic | 3.0 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.0:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.1 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.1:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.2 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.2:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.3 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.3:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.4 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.4:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.5 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.5:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.6 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.6:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.7 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.7:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.8 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.8:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.9 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.9:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.10 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.10:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.11 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.11:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.12 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.12:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.13 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.13:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.14 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.14:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.15 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.15:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.16 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.16:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.17 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.17:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.18 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.18:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.19 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.19:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.20 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.20:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.21 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.21:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.22 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.22:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.23 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.23:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.24 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.24:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.25 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.25:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.26 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.26:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.27 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.27:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.28 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.28:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.29 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.29:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.30 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.30:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.31 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.31:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.32 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.32:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.33 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.33:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.34 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.34:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.35 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.35:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.36 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.36:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.37 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.37:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.38 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.38:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.39 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.39:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.40 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.40:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.41 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.41:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.42 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.42:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.43 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.43:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.44 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.44:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.45 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.45:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.46 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.46:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.47 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.47:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.48 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.48:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.49 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.49:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.50 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.50:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.51 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.51:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.52 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.52:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.53 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.53:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.54 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.54:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.55 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.55:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.56 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.56:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.57 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.57:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.58 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.58:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.59 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.59:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.60 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.60:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.61 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.61:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.62 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.62:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.63 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.63:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.64 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.64:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.65 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.65:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.66 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.66:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.67 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.67:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.68 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.68:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.69 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.69:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.70 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.70:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.71 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.71:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.72 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.72:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.73 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.73:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.74 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.74:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.75 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.75:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.76 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.76:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.77 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.77:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.78 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.78:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.79 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.79:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.80 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.80:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.81 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.81:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.82 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.82:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.83 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.83:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.84 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.84:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.85 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.85:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.86 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.86:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.87 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.87:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.88 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.88:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.89 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.89:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.90 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.90:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | 3.91 | - | - |
cpe:2.3:a:binary-husky:gpt_academic:3.91:*:*:*:*:*:*:*
|
| binary-husky | gpt_academic | * | - | - |
cpe:2.3:a:binary-husky:gpt_academic:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
4.0 (cna)
MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
3.0 (cna)
MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
2.0 (cna)
MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-10236 |
2025-11-11 15:23:01 | 2025-11-11 07:40:03 |
| NVD | nvd_CVE-2025-10236 |
2025-11-11 15:01:02 | 2025-11-11 07:47:54 |
| CNNVD | cnnvd_CNNVD-202509-1727 |
2025-11-11 15:12:57 | 2025-11-11 08:00:10 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 路径遍历
- cnnvd_id: 未提取 -> CNNVD-202509-1727
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 92 -> 93
- data_sources: ['cve'] -> ['cve', 'nvd']