CRITICAL
gpt-researcher
CVE published 2026-08-27
CVE-2026-37006
A critical vulnerability exists in gpt-researcher v0.14.7 and earlier versions, affecting the WebSocket endpoint. This allows an unauthenticated remote attacker to execute code via malicious Model Context Protocol configurations. The CVSS score is 9.8, indicating critical severity. Defenders should assess exposure and apply patches or mitigations. The vulnerability class is related to improper handling of [truncated]