CVE-2026-0763Patch(binary-husky / gpt_academic)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch binary-husky gpt_academic systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to exploit this vulnerability. The specific flaw exists within the run_in_subprocess_wrapper_func function. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27958.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gpt_academic

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
gpt_academic

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-06: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-06: 104-06
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • SonicWall@SonicWall
    Patch

    CVE-2026-0763 affects GPT Academic, an open-source LLM tool with 70K+ GitHub stars. SonicWall Capture Labs assessed the CVSS 9.8 flaw and developed protections against it. Read the research for mitigation steps. https://bit.ly/3NZWZBZ https://t.co/2O4pHcSUPC

    Post summary

    SonicWall Capture Labs has analyzed CVE-2026-0763, rated CVSS 9.8, and released mitigation instructions to protect users of the GPT Academic LLM tool.

    10010190
    29.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbinary-huskygpt_academic3.91--

Explore more