CVE-2025-65720: Command Injection
Published Jul 15, 2026
·Updated
An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.
Affected Software
1 affected component
Open Source GPT Researcher GPT Researcher=3.3.7
Event History
Apr 16, 2026
News Published
via The Register·10:45 PM
News Published
via The Register·10:49 PM
Jul 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-65720?
The severity of CVE-2025-65720 is critical with a score of 9.8.
2
What does CVE-2025-65720 allow an attacker to do?
CVE-2025-65720 allows attackers to execute arbitrary commands on a victim system through user interaction with a crafted HTML page.
3
What version of software is affected by CVE-2025-65720?
CVE-2025-65720 affects Open Source GPT Researcher version 3.3.7.
4
What is the primary vulnerability type of CVE-2025-65720?
The primary vulnerability type of CVE-2025-65720 is command injection.
5
How can users protect themselves from CVE-2025-65720?
Users can protect themselves from CVE-2025-65720 by avoiding interaction with untrusted HTML pages that may exploit this vulnerability.