CVE-2026-5630

A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

06 Apr 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-06 07:16

Updated : 2026-06-17 10:59


NVD link : CVE-2026-5630

Mitre link : CVE-2026-5630

CVE.ORG link : CVE-2026-5630


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')