PatchSiren

papersgpt CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL papersgpt CVE published 2026-08-11

CVE-2026-73032

CVE-2026-73032 PapersGPT for Zotero 0.6.1 remote code execution vulnerability allows attackers to execute arbitrary JavaScript via malicious LLM endpoint responses. Users should assess exposure, prioritize remediation, and verify affected versions. This vulnerability is caused by unsanitized input to window.eval() in views.ts, enabling attackers to execute code in Zotero's chrome-privileged context. Succe [truncated]