CVE-2024-10956 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attac…
High CVSS: 7.1

CVE-2024-10956

GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server, enabling unauthorized actions such as deleting conversation history without the victim's consent. The issue arises due to insufficient WebSocket authentication and lack of origin validation.
Vendor
Binary-husky
Product
Gpt Academic
CWE
CWE-346
Yayın Tarihi
2025-03-20 10:15:22
Güncelleme
2025-07-15 11:15:23
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar