PT-2026-60309 · Unknown · Gpt-Researcher

CVE-2025-65720

·

Published

2026-07-15

·

Updated

2026-07-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPT Researcher version 3.3.7
Description An issue allows attackers to execute arbitrary commands on a victim system through command injection. This occurs when a user interacts with a specially crafted HTML page, and no authentication is required to trigger the flaw.
Recommendations Update GPT Researcher to a version newer than 3.3.7.

Fix

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65720

Affected Products

Gpt-Researcher