CVE-2026-37012: PentestGPT PentestGPT vulnerability
Published Aug 27, 2026
·Updated
A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user telemetry data via hardcoded API credentials.
Affected Software
1 affected component
PentestGPT PentestGPT=1.0.0
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Who is exposed to this issue?
Deployments of PentestGPT 1.0.0 that use the affected pentestgpt/core/langfuse.py component are exposed. The disclosed information is sensitive user telemetry data.
2
What does an attacker need to exploit it?
The issue is described as remotely exploitable through hardcoded API credentials. No additional attacker prerequisites are provided in the available data.
3
Is a fixed version available?
The available data identifies PentestGPT 1.0.0 as affected but does not provide a fixed version or patch guidance.