CVE-2026-5633 | assafelovic gpt-researcher up to 3.4.3 ws Endpoint source_urls server-side request forgery (Issue 1696)
A vulnerability, which was classified as critical, was found in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery.
This vulnerability is registered as CVE-2026-5633. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.