CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsan...
Added to the CISA Known Exploited Vulnerabilities catalog on 11 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.6.
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt injection in PDFs, MI...
Required action: Review and patch if applicable to your AI infrastructure.