External risk intelligence

gpt-researcher WebSocket Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-37006

The vulnerability exists in a WebSocket endpoint within a web-based application framework. As a web application, it is commonly deployed as a network-accessible service, making the WebSocket interface reachable in standard deployment configurations.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in the WebSocket endpoint of gpt-researcher software could allow unauthenticated remote attackers to execute code by providing specially crafted Model Context Protocol configurations. This issue affects the integrity and availability of systems using this technology.

  • Unauthenticated code execution via malicious configurations.
  • Potential for widespread compromise if technology is affected.
  • Confirm relevance and exposure of this technology.

Attack Path

How an attacker could exploit the issue

An attacker could send specially crafted configurations to the WebSocket endpoint of gpt-researcher. This could then lead to code execution on the server.

  • Unauthenticated remote access to WebSocket.
  • Malicious Model Context Protocol configuration.
  • Server-side code execution.

Live Threat

Current exploitation, exposure, and threat context

A vulnerability in the WebSocket endpoint of gpt-researcher could allow an unauthenticated remote attacker to execute arbitrary code by sending specially crafted Model Context Protocol configurations. This could affect the integrity and availability of the service and any data it processes.

  • Arbitrary code execution on the server.
  • Malicious configurations sent over WebSocket.
  • Compromised service and potential data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in gpt-researcher's WebSocket endpoint presents a critical risk, allowing unauthenticated remote code execution. Owners of applications utilizing this tool, likely development or research teams, must prioritize identifying all instances of gpt-researcher. The immediate next step involves confirming its network exposure, business criticality, and then coordinating remediation with infrastructure or security teams to mitigate the risk.

  • Application owners must identify instances.
  • Verify network exposure and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is gpt-researcher?

gpt-researcher is an open-source software framework designed to automate online research tasks. It uses artificial intelligence to scan web sources, process information, and compile reports. It is frequently utilized by developers and data analysts to build custom research agents that gather and summarize large amounts of data automatically.

How does CVE-2026-37006 allow code execution?

This vulnerability relates to Improper Authentication, classified as CWE-287. It occurs because the WebSocket endpoint fails to properly verify the identity of the person connecting to it. An attacker can exploit this lack of authentication to inject malicious Model Context Protocol configurations, which the server then incorrectly executes.

When does this vulnerability trigger?

The vulnerability triggers when an attacker sends a malicious Model Context Protocol configuration to the application's WebSocket endpoint. This process does not require any prior authentication or special user permissions. It is important to note that merely viewing or browsing the legitimate web interface of the application is not the trigger; the attack specifically targets the background WebSocket communication channel.

Is my instance of gpt-researcher at risk?

If your application is accessible over a network, it is at higher risk. According to Halo Surface Signal, because this technology operates as a web-based service with a WebSocket interface, it is often reachable in standard deployments. You should consider any instance that can be accessed via the internet or an untrusted network as having a higher potential for external exposure.

Do I need to patch gpt-researcher immediately?

Yes, you should prioritize this issue. First, locate all active instances of the software within your infrastructure. Once identified, verify their specific network accessibility and business purpose. Coordinate with your technical team to restrict access to the WebSocket endpoint and verify if an updated version is available to replace your current installation.

References