Executive brief
GPT Researcher, an autonomous AI research agent, contains a critical security flaw where its web interface and API are completely unprotected. This allows anyone on the network to remotely access the tool without a password to read private research reports, upload or delete files, and trigger expensive AI tasks that consume the owner's API credits. Because the application lacks any built-in login system, an attacker could effectively take over the service and its data.
Technical details
The FastAPI-based backend of gpt-researcher (specifically in backend/server/app.py) fails to implement any authentication middleware, API key validation, or session management. This architectural omission exposes 14 critical endpoints, including those for file uploads, file deletion, and research task generation. A remote attacker can exploit this to exfiltrate research data, perform arbitrary file operations, or cause financial impact by triggering unlimited LLM API calls. The vulnerability is present in the default configuration, which binds to all network interfaces (0.0.0.0). As of the advisory date, the project has not released a patch, and the application lacks any internal authentication constructs.
Affected products
- assafelovic gpt-researcher <= 3.4.3
Timeline
- 2026-03-19: disclosed: Vulnerability discovered and reported via GitHub issue #1695
- 2026-04-06: advisory: Initial CVE publication