{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/papersgpt-for-zotero-0.6.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-73032"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PapersGPT for Zotero (0.6.1)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["PapersGPT"],"content_html":"\u003cp\u003ePapersGPT for Zotero version 0.6.1 contains a high-severity remote code execution (RCE) vulnerability that stems from the improper handling of responses from large language model (LLM) endpoints. Specifically, the application's 'views.ts' component passes unsanitized content returned by LLMs directly into the 'window.eval()' function. This insecure implementation allows an attacker to execute arbitrary JavaScript in the context of Zotero's chrome-privileged environment. By leveraging techniques such as PDF-based prompt injection, man-in-the-middle (MITM) interception of API requests, or configuring the extension to use a malicious custom LLM endpoint, an attacker can escape the application sandbox. Successful exploitation grants the attacker extensive capabilities on the host system, including unauthorized file system read/write operations, process execution, and access to all sensitive data stored within the Zotero application. Given that the extension operates with high-level privileges within the browser or desktop shell, this vulnerability poses a significant risk to user data and system integrity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target user utilizing the PapersGPT for Zotero extension (version 0.6.1).\u003c/li\u003e\n\u003cli\u003eAttacker sets up a malicious LLM endpoint or performs MITM interception on the extension's network traffic.\u003c/li\u003e\n\u003cli\u003eAttacker triggers an interaction within the Zotero interface that prompts a request to the LLM endpoint (e.g., summarizing a PDF).\u003c/li\u003e\n\u003cli\u003eThe malicious LLM endpoint returns a crafted payload containing arbitrary JavaScript code wrapped in a response expected by the extension.\u003c/li\u003e\n\u003cli\u003eThe extension receives the response and passes the unsanitized payload to 'window.eval()' inside 'views.ts'.\u003c/li\u003e\n\u003cli\u003eThe JavaScript payload executes within the chrome-privileged context of the Zotero application.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the privileged context to execute system commands or interact with the local file system.\u003c/li\u003e\n\u003cli\u003eFull system impact is achieved, including data exfiltration and persistent local code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full compromise of the local Zotero environment and the underlying host system. An attacker can access all stored research data, read or write arbitrary files, and execute arbitrary processes with the permissions of the user running Zotero. Because Zotero runs as a desktop application, this effectively bypasses standard web-extension isolation, potentially impacting all research-heavy environments where this tool is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update or remove the PapersGPT for Zotero extension if a patch is available from the vendor.\u003c/li\u003e\n\u003cli\u003eFor enterprise environments, use endpoint management tools to block the extension 'PapersGPT' globally until version 0.6.2 or later is verified as installed.\u003c/li\u003e\n\u003cli\u003eAudit network traffic originating from Zotero to identify connections to unauthorized or anomalous LLM endpoints.\u003c/li\u003e\n\u003cli\u003eRestrict Zotero's network access via host-based firewalls to strictly defined, legitimate LLM API domains to mitigate the impact of MITM-based exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-11T21:49:40Z","date_published":"2026-08-11T21:49:40Z","id":"https://feed.craftedsignal.io/briefs/2026-08-papersgpt-rce/","summary":"PapersGPT for Zotero 0.6.1 is vulnerable to remote code execution due to unsanitized LLM responses being passed to window.eval(), allowing full system access.","title":"Remote Code Execution in PapersGPT for Zotero","url":"https://feed.craftedsignal.io/briefs/2026-08-papersgpt-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - PapersGPT for Zotero (0.6.1)","version":"https://jsonfeed.org/version/1.1"}