Product
PapersGPT for Zotero 0.6.1 is vulnerable to remote code execution due to unsanitized LLM responses being passed to window.eval(), allowing full system access.