{"id":"CVE-2025-65720","aliases":["GHSA-8j86-h8gg-797p"],"title":"GPT Researcher MCP STDIO configuration allows remote command execution","summary":"GPT Researcher MCP STDIO configuration allows remote command execution","severity":"critical","cvss":9.8,"cwe":["CWE-77"],"vendor":"gpt-researcher","product":"gpt-researcher","ecosystem":"pip","affected":["gpt-researcher >= 0.14.5, <= 0.14.7"],"published":"2026-07-16","updated":"2026-10-02","sourceUpdated":"2026-10-02T22:38:52Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-8j86-h8gg-797p","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65720"},{"url":"https://github.com/assafelovic/gpt-researcher"},{"url":"https://www.ox.security/blog/gpt-researcher-remote-code-execution"},{"url":"https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem"},{"url":"https://github.com/advisories/GHSA-8j86-h8gg-797p"}],"tags":["ghsa","pip"],"epss":0.00892,"epssPercentile":0.58005,"ingestedAt":"2026-10-02T23:34:57.404Z","slug":"CVE-2025-65720","body":"## Overview\n\nAn issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.\n\n## Affected packages\n\n- `gpt-researcher >= 0.14.5, <= 0.14.7`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}