CVE-2026-37006

A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.

  • Published Aug 27, 2026
  • CVSS 9.8 critical
  • 0.9% chance of exploitation in the next 30 days (EPSS)

CVE-2026-37006 at the National Vulnerability Database