A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-5632 is an authentication bypass vulnerability in gpt-researcher versions up to 3.4.3 affecting HTTP REST API endpoints, allowing remote attackers to manipulate requests without proper authentication. The vulnerability has public exploits available and poses a significant risk to organizations using vulnerable versions of this research tool.
تؤثر هذه الثغرة على مكون HTTP REST API في gpt-researcher مما يسمح بتجاوز آليات المصادقة. يمكن للمهاجمين الوصول عن بعد إلى الخدمة دون بيانات اعتماد صحيحة. توفر الاستغلالات العامة خطراً فوري للمنظمات التي تستخدم الإصدارات المتأثرة.
A critical authentication bypass flaw exists in gpt-researcher up to version 3.4.3 in the HTTP REST API component, enabling remote unauthorized access without proper credentials. Public exploits are available for this vulnerability, increasing the risk for Saudi organizations deploying this tool.
Immediately upgrade gpt-researcher to version 3.4.4 or later. Implement network-level access controls and API authentication mechanisms. Monitor API endpoints for suspicious activity. Apply Web Application Firewall (WAF) rules to restrict unauthorized API access. Disable or restrict HTTP REST API endpoints if not required for operations.
قم بترقية gpt-researcher فوراً إلى الإصدار 3.4.4 أو أحدث. طبق آليات التحكم في الوصول على مستوى الشبكة والمصادقة. راقب نقاط نهاية API للنشاط المريب. طبق قواعد جدار الحماية لتقييد الوصول غير المصرح. عطل أو قيد نقاط نهاية HTTP REST API إذا لم تكن مطلوبة.