← Back to CVE search

CVE-2026-37006

gpt-researcher

Description

A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.

EPSS 0.27%Risk 0
View source
Published
2026-08-27 20:17:41
Affected versions
<=0.14.7
Type
Library
Last modified
2026-08-27 20:17:41
Vector
Pending