CVE-CVE-2026-82286
Severity
HIGH
CVSS Score
8.6
Description
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files with content sourced from attacker-controlled URLs....
PoCs for CVE-CVE-2026-82286
CVE-2026-82286-gpt-crawler-Arbitrary-File-Write
General
Python
0
BiiTts
2026-08-29