GPT Academic Deserialization of Untrusted Data Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in GPT Academic due to deserialization of untrusted data in the stream_daas function. This issue arises from inadequate validation of user-supplied data, allowing remote attackers to execute arbitrary code with root privileges. Exploitation requires interaction with a malicious DAAS server, and the attack vectors may vary based on the implementation.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system, with the executed code running in the context of the root user.

Remediation

The primary mitigation strategy is to restrict interactions with the product.

Added: Jan 23, 2026, 4:38 AM
Updated: Jan 23, 2026, 4:38 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.1
remediation
7.9
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.