CVE-2026-5632 | assafelovic gpt-researcher up to 3.4.3 HTTP REST API Endpoint missing authentication (Issue 1695)
A vulnerability, which was classified as critical, has been found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication.
This vulnerability is cataloged as CVE-2026-5632. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.