CVE-2026-73032: PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav
Summary
PapersGPT for Zotero 0.6.1 has a remote code execution vulnerability (RCE, where attackers can run commands on a system they don't own) that lets attackers execute malicious JavaScript code by tricking the AI into returning harmful instructions through prompt injection (hiding malicious commands in AI inputs), intercepting network traffic, or using a fake AI endpoint. This gives attackers dangerous abilities like reading and writing files, running programs, and stealing all data in Zotero (a research management tool).
Vulnerability Details
9.6(critical)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
network
low
none
required
August 11, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73032
First tracked: August 11, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 92%