CVE-2026-37006
gpt-researcher · gpt-researcher
A critical vulnerability in the gpt-researcher WebSocket endpoint allows unauthenticated remote attackers to execute arbitrary code using malicious Model Context Protocol configurations.
Executive summary
An unauthenticated remote code execution vulnerability in gpt-researcher version 0.14.7 and earlier poses a critical risk of full system compromise.
Vulnerability
This flaw exists within the WebSocket endpoint of the application, which fails to properly validate inputs, allowing unauthenticated remote attackers to trigger code execution through malicious Model Context Protocol configurations.
Business impact
The ability for an unauthenticated attacker to achieve remote code execution represents the most severe security risk, as it allows for complete system takeover. With a CVSS score of 9.8, this vulnerability permits unauthorized access to sensitive data, potential lateral movement within the network, and full control over the affected research instances, leading to significant operational disruption and data loss.
Remediation
Immediate Action: Since no specific patch version is currently identified, administrators should restrict access to the gpt-researcher WebSocket endpoint at the network or application firewall level until a vendor-supplied update is available.
Proactive Monitoring: Monitor server logs for unusual WebSocket connection patterns or unauthorized requests directed at the research service, particularly those involving Model Context Protocol headers.
Compensating Controls: Implement strict network segmentation and egress filtering to prevent the application from making unauthorized outbound connections if the service is compromised.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical CVSS severity and the ease of exploitation over the network, organizations using gpt-researcher should treat this as a high-priority incident. Until a formal patch is released, ensure the application is not exposed to the public internet and restrict access to trusted internal networks only.