CVE-2026-5630Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-06: 3Technical Details · 2026-04-06: 204-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5630 - assafelovic gpt-researcher Report API http://app.py cross site scripting Intel Report: https://ift.tt/TZD9mKr

    Post summary

    The alert announces CVE‑2026‑5630 as a cross‑site scripting flaw in the Report API, attributed to assafelovic and a gpt‑researcher, and provides an Intel report link for further details.

    0000034
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5630 A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report A… https://www.cve.org/CVERecord?id=CVE-2026-5630 ----- Traducción: CVE-2026-5630 Se … http://infoflow.cloud`

    Post summary

    A new CVE, CVE‑2026‑5630, has been identified for assafelovic gpt‑researcher 3.4.3, affecting an unknown function in backend/server/app.py, but no PoC, exploit code, active exploitation, or patch information is provided.

    0000033
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5630 A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report A… https://www.cve.org/CVERecord?id=CVE-2026-5630

    Post summary

    The statement announces CVE-2026-5630 as a flaw in the gpt-researcher component, but provides only minimal details and no actionable information.

    00000446
    57.0K followersView on X

Explore more