Executive brief
gpt-researcher is a framework for autonomous AI research agents. A vulnerability in its WebSocket endpoint allows unauthenticated remote attackers to execute arbitrary code by sending malicious Model Context Protocol configurations, potentially compromising servers running affected versions and enabling full system control.
Technical details
The vulnerability is a remote code execution flaw in the WebSocket endpoint of gpt-researcher v0.14.7 and earlier. An unauthenticated attacker can send specially crafted Model Context Protocol (MCP) configurations over the WebSocket connection to trigger code execution on the server. The WebSocket endpoint lacks proper input validation and authentication controls, allowing the attack to be conducted without credentials from a network-accessible position. Successful exploitation grants the attacker arbitrary code execution in the context of the application.
Affected products
- gpt-researcher gpt-researcher v0.14.7 and before
Timeline
- 2026-08-27: disclosed