Prompt Injection Leading to RCE in binary-husky/gpt_academic Plugin `manim`
Vulnerability Description
In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. This allows an attacker to perform remote code execution (RCE) on the app backend server by injecting malicious code through the prompt.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10954
Credits & Attribution
No credits recorded in the NVD database.
More from binary-husky
View All →Affected Vendor
binary-husky
View all reports →