CVE-2026-5633
Last modified
CVE-2026-5633 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-5633?
How severe is CVE-2026-5633?
How do I fix CVE-2026-5633?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56324Capgo before 12.128.2 contains a rate limit bypass vulnerabi…8.8
- CVE-2026-56325Capgo before 12.128.2 uses ILIKE pattern matching instead of…3.1
- CVE-2026-56326Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 conta…6.1
- CVE-2026-56327Capgo before 12.128.2 contains an information disclosure vul…6.9
- CVE-2026-56328Capgo before 12.128.2 allows multiple public channels for th…7.1
- CVE-2026-56329Capgo before 12.128.2 contains a cross-tenant preview namesp…6.4
- CVE-2026-56330Capgo before 12.128.2 contains an open redirect vulnerabilit…4.8
- CVE-2026-56331Capgo before 12.128.2 contains improper error handling in th…6.9
- CVE-2026-56332Capgo before 12.128.2 contains an open redirect vulnerabilit…5.1
- CVE-2026-56333Capgo before 12.128.2 contains a server-side validation bypa…5.3
- CVE-2026-56334Capgo before 12.128.2 lacks an UPDATE row-level security pol…5.3
- CVE-2026-56335Capgo before 12.128.2 contains an authorization bypass vulne…7.1
Are you affected by CVE-2026-5633?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
