CVE-2026-5633Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-06: 3Technical Details · 2026-04-06: 204-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5633 - assafelovic gpt-researcher ws Endpoint server-side request forgery Intel Report: https://ift.tt/RUMvI3T

    Post summary

    The alert announces the existence of a new CVE (CVE‑2026‑5633) identified as a server‑side request forgery vulnerability, but provides no PoC, exploit code, or evidence of active exploitation.

    0000049
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5633 A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the … https://www.cve.org/CVERecord?id=CVE-2026-5633 ----- Traducción: CVE-2026-5633 Se … http://infoflow.cloud`

    Post summary

    The tweet is a brief disclosure of CVE‑2026‑5633 for the assafelovic gpt‑researcher component, providing minimal technical details and a link to the CVE record but no PoC, exploit or patch information.

    0000028
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5633 A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the … https://www.cve.org/CVERecord?id=CVE-2026-5633

    Post summary

    The post references CVE-2026-5633 with minimal, vague details, without any PoC, exploit code, patch, or technical specifics.

    00000235
    57.0K followersView on X

Explore more