Cross Site Scripting in assafelovic gpt-researcher Affected by Vulnerability
CVE-2026-5630
Key Information:
- Vendor
Assafelovic
- Status
- Vendor
- CVE Published:
- 6 April 2026
Badges
What is CVE-2026-5630?
A significant flaw resides in the Report API of the assafelovic gpt-researcher software, specifically within an undisclosed function found in backend/server/app.py. This vulnerability permits remote attackers to perform cross-site scripting (XSS) attacks. Despite being informed through an issue report, the project maintainers have yet to respond. The exploit has been made public and poses a risk to users until patched. It is critical for users of affected versions to assess their exposure and implement necessary safeguards.
Affected Version(s)
gpt-researcher 3.4.0
gpt-researcher 3.4.1
gpt-researcher 3.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
