CVE-2026-37006: Gpt-researcher vulnerability
Published Aug 27, 2026
·Updated
A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.
Affected Software
1 affected component
gpt-researcher<=0.14.7
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Which deployments are affected?
gpt-researcher version 0.14.7 and earlier are affected where the WebSocket endpoint is available to a remote attacker.
2
Does an attacker need an account or valid credentials?
No. The issue can be exploited by an unauthenticated remote attacker using malicious Model Context Protocol configurations.