CVE-2026-5632Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (5 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Exploit: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-06: 5PoC Mentioned / Linked · 2026-04-06: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-06: 304-06
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Exploit
120.0%
Referenced assets4 URLs
Full discourse5 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5632 - assafelovic gpt-researcher HTTP REST API Endpoint missing authentication Intel Report: https://ift.tt/Zr0lNFy

    Post summary

    The post announces CVE‑2026‑5632, describing an unauthenticated HTTP REST API endpoint in the assafelovic gpt‑researcher application.

    0000031
    281 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5632 - assafelovic gpt-researcher HTTP REST API Endpoint missing authentication Intel Report: https://ift.tt/H3X5uIp

    Post summary

    An alert lists CVE‑2026‑5632 as a missing authentication flaw in an HTTP REST API endpoint, but offers no PoC, exploit code, active exploitation evidence, or patch information.

    0000044
    281 followersView on X
  • DFIR Lab@DFIR_Lab
    Exploit

    🚨 HIGH: CVE-2026-5632 (CVSS 7.3) - Missing authentication in gpt-researcher ≤3.4.3 HTTP REST API. Remotely exploitable, public exploit available. Vendor unresponsive. Patch/restrict access immediately. #CVE #Vulnerability #PatchNow #ThreatIntel

    Post summary

    CVE-2026-5632 exposes a missing authentication flaw in gpt-researcher’s REST API, is remotely exploitable with a publicly available exploit, and requires immediate patching to prevent potential attacks.

    0000034
    1 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5632 A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation… https://www.cve.org/CVERecord?id=CVE-2026-5632 ----- Traducción: CVE-2026-5632 Se … http://infoflow.cloud`

    Post summary

    The post confirms the existence of CVE-2026‑5632 in assafelovic gpt‑researcher but offers no additional technical detail, PoC, exploit, or patch information.

    0000032
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5632 A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation… https://www.cve.org/CVERecord?id=CVE-2026-5632

    Post summary

    The post announces a new CVE (CVE-2026-5632) discovered in assafelovic gpt-researcher v3.4.3, stating it affects an unknown function of an HTTP REST API endpoint, with no further exploitation, patch, or technical detail provided.

    00000296
    57.0K followersView on X

Explore more