An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. The NVD entry is currently Awaiting Analysis. This CVE was published on 2026-07-15T22:16:45.417Z and was last modified on 2026-07-16T19:16:44.107Z. The vulnerability has a CVSS score of 9.8, indicating critical severity. It is associated with CWE-77 [truncated]
A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3, affecting an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. The vulnerability can be exploited remotely. The project was informed of the problem early through an issue report but has not responded yet. Users of assafelovic gpt-researcher up [truncated]
A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. Users o [truncated]
A code injection vulnerability was found in assafelovic gpt-researcher up to 3.4.3. The vulnerability affects the function extract_command_data in the file backend/server/server_utils.py of the ws Endpoint component. The attack may be performed remotely and has been disclosed to the public. This vulnerability has a CVSS score of 5.5, indicating a medium severity level. Users of assafelovic gpt-researcher [truncated]