PatchSiren

gpt-researcher CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL gpt-researcher CVE published 2026-08-27

CVE-2026-37006

A critical vulnerability exists in gpt-researcher v0.14.7 and earlier versions, affecting the WebSocket endpoint. This allows an unauthenticated remote attacker to execute code via malicious Model Context Protocol configurations. The CVSS score is 9.8, indicating critical severity. Defenders should assess exposure and apply patches or mitigations. The vulnerability class is related to improper handling of [truncated]