CVE-2026-37006

gpt-researcher · gpt-researcher

A critical vulnerability in the gpt-researcher WebSocket endpoint allows unauthenticated remote attackers to execute arbitrary code using malicious Model Context Protocol configurations.

Executive summary

An unauthenticated remote code execution vulnerability in gpt-researcher version 0.14.7 and earlier poses a critical risk of full system compromise.

Vulnerability

This flaw exists within the WebSocket endpoint of the application, which fails to properly validate inputs, allowing unauthenticated remote attackers to trigger code execution through malicious Model Context Protocol configurations.

Business impact

The ability for an unauthenticated attacker to achieve remote code execution represents the most severe security risk, as it allows for complete system takeover. With a CVSS score of 9.8, this vulnerability permits unauthorized access to sensitive data, potential lateral movement within the network, and full control over the affected research instances, leading to significant operational disruption and data loss.

Remediation

Immediate Action: Since no specific patch version is currently identified, administrators should restrict access to the gpt-researcher WebSocket endpoint at the network or application firewall level until a vendor-supplied update is available.

Proactive Monitoring: Monitor server logs for unusual WebSocket connection patterns or unauthorized requests directed at the research service, particularly those involving Model Context Protocol headers.

Compensating Controls: Implement strict network segmentation and egress filtering to prevent the application from making unauthorized outbound connections if the service is compromised.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical CVSS severity and the ease of exploitation over the network, organizations using gpt-researcher should treat this as a high-priority incident. Until a formal patch is released, ensure the application is not exposed to the public internet and restrict access to trusted internal networks only.

Sources