A high-severity remote code execution flaw tracked as CVE-2026-73032 was disclosed in PapersGPT for Zotero affecting versions up to and including 0.6.1. The bug stems from passing untrusted LLM-generated content to window.eval() in views.ts, allowing arbitrary JavaScript execution inside Zotero's chrome-privileged context. Reported attack paths include prompt injection embedded in PDFs, man-in-the-middle tampering with API responses, and malicious custom LLM endpoints, with potential impact including file read/write access, process execution, and exposure of all Zotero data.
The maintainers addressed the issue by merging pull request #155, which removed window.eval from the execTag functionality and replaced another eval-based regex path with safer handling using new RegExp(...). The fix was merged into the main branch and tagged in papersgpt-v1.1.0, while public advisories classified the weakness as CWE-94 and noted proof-of-concept exploitation with high confidentiality, integrity, and availability impact.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
An SSVC assessment was added to CVE-2026-73032 listing CISA Coordinator as the role and marking exploitation as proof-of-concept, not automatable, with total technical impact.
The CVE record for CVE-2026-73032 was newly received by disclosure@vulncheck.com and later modified the same day. The record identified PapersGPT for Zotero versions up to and including 0.6.1 as affected and added references to the repository, fixing commit, issue, pull request, and VulnCheck advisory.
VulnCheck published an advisory describing a remote code execution vulnerability in PapersGPT for Zotero 0.6.1 caused by unsanitized LLM output being passed to window.eval() in views.ts. The advisory documented exploitation vectors including prompt injection in PDFs, man-in-the-middle interception, and malicious custom LLM endpoints.
A verified commit removing window.eval of LLM responses in src/modules/views.ts was authored and merged via pull request #155 into the main branch. The patch also replaced eval-based regex handling and was associated with release tag papersgpt-v1.1.0.
A pull request was published to remove use of window.eval on LLM-generated output in the execTag function and replace another eval-based regex path with new RegExp, addressing a CWE-94 code injection issue in PapersGPT for Zotero.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.