CRITICAL
papersgpt
CVE published 2026-08-11
CVE-2026-73032
CVE-2026-73032 PapersGPT for Zotero 0.6.1 remote code execution vulnerability allows attackers to execute arbitrary JavaScript via malicious LLM endpoint responses. Users should assess exposure, prioritize remediation, and verify affected versions. This vulnerability is caused by unsanitized input to window.eval() in views.ts, enabling attackers to execute code in Zotero's chrome-privileged context. Succe [truncated]