{"apiVersion":"1.0","identifier":"CVE-2026-37006","description":"A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.","publishedAt":"2026-08-27T20:17:41","lastModifiedAt":"2026-08-27T20:17:41","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-37006","cvssScore":null,"cvssVector":"Pending","epssProbability":0.0027,"riskScore":0,"affectedProduct":"gpt-researcher","affectedVersions":"<=0.14.7","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-37006","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-37006","en":"https://www.redsauce.net/en/cves/CVE-2026-37006","fr":"https://www.redsauce.net/fr/cves/CVE-2026-37006","pt":"https://www.redsauce.net/pt/cves/CVE-2026-37006","de":"https://www.redsauce.net/de/cves/CVE-2026-37006","sk":"https://www.redsauce.net/sk/cves/CVE-2026-37006","el":"https://www.redsauce.net/el/cves/CVE-2026-37006"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-37006"}}