YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0031

Register entry

gpt_academic path traversal via URL-encoded file parameter, found by Vulnhuntr

CVE
CVE-2024-10100
Project
binary-husky/gpt_academic
Finder
Vulnhuntr
Autonomy
LLM with Jedi static parsing, Python only; findings routed through huntr
Evidence tier
Claim outside the record
Assigner
@huntr_ai
Severity
6.5 Medium (CVSS 3.1)
Bounty
huntr.com; amount unpublished
Confidence
CONFIRMED

What happened

A path traversal via URL-encoded file parameter in binary-husky/gpt_academic, assigned by huntr with an empty credits array, listed in the Vulnhuntr README under "World's first autonomous AI-discovered 0day vulnerabilities". Product, class, date and CVSS reproduce at the record; the affected version numbers in circulation trace to huntr pages this desk has not opened.

Credit as recorded: credits array empty; attribution in the Vulnhuntr README. Date basis: datePublished.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026