Tools AI-Found Vulnerability Register aifv-0037
Register entry
gpt-researcher arbitrary file overwrite, found by Vulnhuntr and fixed as a pull request
- Project
- assafelovic/gpt-researcher
- Finder
- Vulnhuntr
- Autonomy
- LLM with Jedi static parsing, Python only; findings routed through huntr
- Evidence tier
- Claim outside the record
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
An arbitrary file overwrite in assafelovic/gpt-researcher fixed as pull request 935, one of two Vulnhuntr finds that landed as a patch rather than a CVE.
Credit as recorded: no CVE; the fix landed as a pull request named in the Vulnhuntr README. Date basis: Vulnhuntr README publication window; the pull request carries its own date.
Sources
- Pull request 935github.com/assafelovic/gpt-researcher/pull/935
- Vulnhuntr READMEraw.githubusercontent.com/protectai/vulnhuntr/main/README.md
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026