PT-2026-30570 · Unknown · Assafelovic Gpt-Researcher

Yu-Bao

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-5631

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions assafelovic gpt-researcher versions up to 3.4.3
Description A code injection issue exists in the extract command data function within the server utils.py file of the ws Endpoint component. Manipulation of the args argument may lead to code injection, potentially allowing for remote attacks. The exploit for this issue has been publicly disclosed, and the project maintainers have not yet responded to reports.
Recommendations Versions prior to 3.4.3 should be updated.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5631

Affected Products

Assafelovic Gpt-Researcher