CVE-2025-65720
Awaiting Analysis Awaiting Analysis - Queue

Command Injection in Open Source GPT Researcher

Vulnerability report for CVE-2025-65720, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-16

Assigner: MITRE

Description

An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-16
Generated
2026-08-05
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open_source_gpt_researcher open_source_gpt_researcher 3.3.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows attackers to run arbitrary commands on a victim's system by tricking them into interacting with a specially crafted HTML page. It exists in Open Source GPT Researcher version 3.3.7.

Detection Guidance

This vulnerability involves arbitrary command execution via user interaction with a crafted HTML page in Open Source GPT Researcher v3.3.7. Detection requires monitoring for suspicious HTML files or user interactions that trigger unexpected commands. Check for recently accessed HTML files in user directories or temporary folders. Review browser history for unusual sites. Use process monitoring tools like ps, top, or Windows Task Manager to detect unexpected command execution. Scan for files with unusual extensions or content in common download locations.

Impact Analysis

Attackers could take control of your system, steal data, install malware, or perform other malicious actions if you interact with the malicious HTML page.

Compliance Impact

The vulnerability allows arbitrary command execution via user interaction with a crafted HTML page, which could lead to unauthorized data access or modification. This may violate compliance requirements under GDPR (data protection) and HIPAA (health information security) if sensitive data is exposed or altered.

Mitigation Strategies

Immediately update Open Source GPT Researcher to the latest version beyond v3.3.7. Avoid opening untrusted HTML pages or disable JavaScript in your browser to prevent command execution. Monitor system logs for suspicious activity related to command execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-65720. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart