UNKNOWNCVE-2026-5633

assafelovic gpt-researcher ws Endpoint server-side request forgery

Platform

nodejs

Component

gpt-researcher

A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

How to fix

Actualice a una versión corregida de gpt-researcher. El desarrollador no ha respondido al informe de vulnerabilidad, por lo que se recomienda verificar si hay versiones alternativas o soluciones alternativas disponibles.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free
CVE-2026-5633 — Vulnerability Details | NextGuard | NextGuard