Junglewise Threat Intelligence

CVE-2026-5630: assafelovic gpt-researcher XSS in Report API

CVE-2026-5630 · Severity: medium · CVSS 4.3 · Published 2026-04-06

Technologies: Assaf Elovic GPT Researcher. Vendors: Assaf Elovic.

Executive brief

A vulnerability has been identified in gpt-researcher, an autonomous AI agent used for conducting deep research. The flaw exists in the Report API component and allows for cross-site scripting (XSS). If exploited, an attacker could execute malicious scripts in a user's browser, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A cross-site scripting (XSS) vulnerability exists in the Report API component of gpt-researcher through version 3.4.3. The issue is located within the backend/server/app.py file, where improper input neutralization allows for the injection of malicious web scripts. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted request to the API. Successful exploitation requires a victim to interact with the malicious content, at which point the attacker's script executes in the context of the victim's browser session. While the project was notified via an issue report, the vulnerability is currently unpatched and has been marked as 'wontfix' by the maintainers.

Affected products

  • assafelovic gpt-researcher up to 3.4.3

Timeline

  • 2026-03-23: disclosed: Issue reported to the project maintainers via GitHub.
  • 2026-04-06: advisory: Vulnerability published by VulDB.

References

Related threats