PT-2026-30570 · Unknown · Assafelovic Gpt-Researcher

·

CVE-2026-5631

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions assafelovic gpt-researcher versions through 3.4.3
Description A code injection issue exists in the extract command data function within the backend/server/server utils.py file, associated with the ws Endpoint component. Manipulation of the args argument can lead to code injection, potentially allowing remote attacks. The exploit for this issue has been publicly disclosed, and the project maintainers have not yet responded to reports about the problem.
Recommendations Versions prior to 3.4.4 should be updated.

Exploit

Fix

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5631

Affected Products

Assafelovic Gpt-Researcher