Impact
The vulnerability exists in the WebSocket endpoint of gpt-researcher v0.14.7 and earlier. An attacker can send crafted Model Context Protocol messages that lead to arbitrary code execution on the server. No authentication is required, meaning any remote host can trigger the flaw. The impact is complete compromise of the target system, giving the attacker the same privileges as the gpt-researcher process.
Affected Systems
Any deployment of gpt-researcher running version 0.14.7 or earlier is affected. This includes installations that expose the WebSocket endpoint publicly or within an organizational network, as no vendor or CPE information distinguishes separate configurations.
Risk and Exploitability
The CVSS score is not provided, but the absence of authentication and the ability to execute code remotely indicate a high exploitability. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog; however, as the attack vector is a remote WebSocket connection, typical attackers can discover and exploit it quickly. The risk is therefore critical, with a potential for full system compromise.
OpenCVE Enrichment