PapersGPT for Zotero RCE via unsanitized LLM response
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability where unsanitized LLM responses are passed to window.eval(), allowing attackers to execute arbitrary JavaScript through prompt injection, MITM interception, or malicious LLM endpoints.
Disclosed 11 August 2026 · Record updated 13 September 2026
Impact
Attackers can execute arbitrary code in Zotero's chrome-privileged context, enabling file read/write, process execution, and access to all Zotero data.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73032
