Junglewise Threat Intelligence

CVE-2025-65720: assafelovic GPT Researcher command injection in MCP STDIO

CVE-2025-65720 · Severity: info · CVSS 8.8 · Published 2026-07-15

Technologies: Assafelovic GPT Researcher. Vendors: Assaf Elovic.

Executive brief

GPT Researcher is an autonomous AI agent used to conduct deep research by scraping and analyzing web data. A security flaw in version 3.3.7 allows an attacker to take control of the system running the agent if the user interacts with a specially crafted malicious webpage during a research task. This could lead to the theft of sensitive data, unauthorized access to local files, or a complete compromise of the host machine.

Technical details

A command injection vulnerability exists in GPT Researcher v3.3.7, stemming from improper handling of inputs within the Model Context Protocol (MCP) STDIO implementation. The flaw allows an attacker to achieve Remote Code Execution (RCE) by tricking a user into interacting with a crafted HTML page while the autonomous agent is conducting research. The root cause is linked to a systemic issue in Anthropic's MCP SDK where unsanitized inputs are passed to system commands. Attackers can exploit this to execute arbitrary shell commands with the privileges of the application. While the NVD entry lists the severity as 'info', the underlying RCE impact typically warrants a High or Critical rating.

Affected products

  • assafelovic GPT Researcher 3.3.7

Timeline

  • 2026-04-15: disclosed: Initial disclosure by OX Security researchers regarding MCP vulnerabilities.
  • 2026-07-15: advisory: CVE-2025-65720 published to the NVD.

References

Related threats