PT-2026-30570 · Unknown · Assafelovic Gpt-Researcher

Yu-Bao

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-5631

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions assafelovic gpt-researcher versions through 3.4.3
Description A code injection issue exists in the extract command data function within the backend/server/server utils.py file, associated with the ws Endpoint component. Manipulation of the args argument can lead to code injection, potentially allowing remote attacks. The exploit for this issue has been publicly disclosed, and the project maintainers have not yet responded to reports about the problem.
Recommendations Versions prior to 3.4.4 should be updated.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5631

Affected Products

Assafelovic Gpt-Researcher