Executive brief
gpt-researcher is an autonomous AI agent used to conduct deep research on various topics. A security vulnerability in its WebSocket interface allows an attacker to inject malicious scripts by manipulating the 'task' argument. If a user is tricked into interacting with a malicious task, it could lead to unauthorized actions being performed in their browser session, potentially compromising sensitive research data or user accounts.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in gpt-researcher versions up to 3.4.3. The flaw is located in the WebSocket interface within the gpt_researcher/skills/researcher.py file, where the 'task' argument is processed without sufficient input sanitization. A remote attacker can exploit this by crafting a malicious task name containing script tags, which are then executed in the context of the victim's browser. This requires user interaction, typically via a social engineering vector. As of the advisory date, the project has been notified but a formal patch has not been confirmed.
Affected products
- assafelovic gpt-researcher up to 3.4.3
Timeline
- 2026-04-06: disclosed: Public disclosure via VulDB and NVD
- 2026-04-06: advisory