CVE-2026-82286: gpt-crawler Arbitrary File Write via outputFileName Parameter

Published Aug 28, 2026
·
Updated

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files with content sourced from attacker-controlled URLs.

Affected Software

1 affected component
gpt-crawler<=1.5.1

Event History

Aug 28, 2026
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Any deployment of gpt-crawler through 1.5.1 that exposes the POST /crawl endpoint to untrusted network clients is exposed, because exploitation does not require authentication.

2

What does an attacker need to exploit it?

An attacker only needs network access to POST /crawl. They can provide an outputFileName containing an absolute path or parent-directory segments and cause content fetched from an attacker-controlled URL to be written to that path.

3

Can existing files be affected?

Yes. The issue allows attackers to overwrite existing files at filesystem paths accessible to the gpt-crawler process.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203