CVE-2026-5630 | assafelovic gpt-researcher up to 3.4.3 Report API backend/server/app.py cross site scripting (Issue 1693 / EUVD-2026-19184)
A vulnerability classified as problematic has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2026-5630. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.