Impact
Vulnerability in the open-source GPT Researcher application version 3.3.7 permits the injection and execution of arbitrary system commands. The flaw corresponds to CWE-77, a command injection weakness, and allows an attacker to run any command with the privileges of the GPT Researcher process when a victim interacts with a malicious HTML page. The high CVSS score of 9.8 reflects the severity and potential impact of this flaw.
Affected Systems
The affected product is the open‑source GPT Researcher platform, specifically release 3.3.7. User‑facing components that process HTML input include the web interface and any web server endpoints that serve user‑generated content. No alternative vendor or product names are listed.
Risk and Exploitability
The EPSS score indicates a very low‑but‑nonzero probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires a user to interact with a crafted HTML page, which can be delivered via phishing or compromised websites. Based on the description, it is inferred that the attacker does not need authenticated or privileged access; the attacker only needs to entice a user to view the malicious content. Once triggered, the attacker can execute any system command with the privileges of the GPT Researcher application, potentially affecting confidentiality, integrity, and availability of the host system.
OpenCVE Enrichment