CVE-2026-5632 is an authentication bypass vulnerability affecting assafelovic gpt-researcher versions up to 3.4.3, specifically within an undocumented HTTP REST API endpoint. The vulnerability allows unauthenticated remote manipulation of the affected component, potentially exposing sensitive functionality to unauthorized access. The vulnerability carries a CVSS 3.1 score of 7.3 (HIGH) with a network-based attack vector requiring no privileges or user interaction. The attack has low complexity and could result in limited compromise of confidentiality, integrity, and availability. The EPSS score of 0.00105 suggests relatively low exploitation likelihood compared to other vulnerabilities in circulation. Public exploit code is available, indicating active awareness in security communities, though the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation campaigns. The development team was notified early through an issue report but has not yet provided a response or security update, leaving affected systems potentially vulnerable pending a patch release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Assafelovic | Gpt-Researcher | 3.4.0, 3.4.1, 3.4.2, 3.4.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.