UNKNOWNCVE-2026-5633
assafelovic gpt-researcher ws Endpoint server-side request forgery
Platform
nodejs
Component
gpt-researcher
A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
How to fix
Actualice a una versión corregida de gpt-researcher. El desarrollador no ha respondido al informe de vulnerabilidad, por lo que se recomienda verificar si hay versiones alternativas o soluciones alternativas disponibles.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free