YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0037

Register entry

gpt-researcher arbitrary file overwrite, found by Vulnhuntr and fixed as a pull request

Project
assafelovic/gpt-researcher
Finder
Vulnhuntr
Autonomy
LLM with Jedi static parsing, Python only; findings routed through huntr
Evidence tier
Claim outside the record
Bounty
None published
Confidence
CONFIRMED

What happened

An arbitrary file overwrite in assafelovic/gpt-researcher fixed as pull request 935, one of two Vulnhuntr finds that landed as a patch rather than a CVE.

Credit as recorded: no CVE; the fix landed as a pull request named in the Vulnhuntr README. Date basis: Vulnhuntr README publication window; the pull request carries its own date.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026