CVE-2026-5631 | assafelovic gpt-researcher up to 3.4.3 ws Endpoint server_utils.py extract_command_data args code injection (Issue 1694 / EUVD-2026-19186)
A vulnerability classified as critical was found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/server_utils.py of the component ws Endpoint. Such manipulation of the argument args leads to code injection.
This vulnerability is listed as CVE-2026-5631. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.