Skip to main content
HIGH

CVE-2024-11039

CVSS v3

8.8

HIGH

EPSS Score

2.1 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows attackers to achieve remote command execution by deserializing untrusted data. The issue arises from the inclusion of numpy in the deserialization whitelist, which can be exploited by constructing a malicious compressed package containing a merge_result.pkl file and a merge_proofread_en.tex file. The vulnerability is fixed in commit 91f5e6b.

Technical details

Published
2025-03-20

Frequently asked questions

What is CVE-2024-11039?

A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows attackers to achieve remote command execution by deserializing untrusted data. The issue arises from the inclusion of numpy in the deserialization whitelist, which can be exploited by constructing a malicious compressed package containing a merge_result.pkl file and a merge_proofread_en.tex file. The vulnerability is fixed in commit 91f5e6b.

Is CVE-2024-11039 actively exploited?

Active exploitation of CVE-2024-11039 has not been confirmed. Its EPSS score was 2.1% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2024-11039?

CVE-2024-11039 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2024-11039 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key