{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-12T21:16:01.605","vulnerabilities":[{"cve":{"id":"CVE-2024-12389","sourceIdentifier":"security@huntr.dev","published":"2025-03-20T10:15:28.247","lastModified":"2025-07-31T19:32:25.923","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation. The Python py7zr package used for extraction does not guarantee that files will remain within the intended extraction directory. An attacker can exploit this vulnerability to perform arbitrary file writes, which can lead to remote code execution."},{"lang":"es","value":"Existe una vulnerabilidad de path traversal en binary-husky/gpt_academic versión git 310122f. La aplicación permite la extracción de archivos 7z proporcionados por el usuario sin la validación adecuada. El paquete Python py7zr utilizado para la extracción no garantiza que los archivos permanezcan en el directorio de extracción previsto. Un atacante puede explotar esta vulnerabilidad para realizar escrituras arbitrarias en archivos, lo que puede provocar la ejecución remota de código."}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-29"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:binary-husky:gpt_academic:2024-10-15:*:*:*:*:*:*:*","matchCriteriaId":"6B6DCF58-F2C2-4491-92A8-BAC81C60A9A4"}]}]}],"references":[{"url":"https://huntr.com/bounties/37afb1c9-bba9-47ee-8617-a5f715271654","source":"security@huntr.dev","tags":["Exploit","Third Party Advisory"]}]}}]}