VYPR

Gpt Crawler

by Builderio

CVEs (1)

  • CVE-2026-82286HigAug 28, 2026
    risk 0.56cvss 8.6epss

    gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-directory segments to overwrite existing files…