CVE-2026-82286 is an unauthenticated arbitrary file-write vulnerability affecting gpt-crawler through version 1.5.1. The POST /crawl endpoint fails to constrain the user-supplied outputFileName parameter to an intended output directory. An attacker can provide an absolute path or parent-directory traversal segments, causing the service to write fetched crawler content to an arbitrary filesystem location accessible to the gpt-crawler service account. Existing files may be overwritten with content obtained from attacker-controlled URLs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This eight-file repository is a Python proof-of-concept and self-contained Docker lab for the claimed CVE-2026-82286 affecting BuilderIO gpt-crawler <= 1.5.1. The main entry point, exploit.py, uses Python urllib to POST an unauthenticated crawler configuration to /crawl. It supplies an attacker-controlled outputFileName plus an attacker-hosted page URL. According to the included code analysis, gpt-crawler validates outputFileName only as a string and later passes a path derived from it directly to fs.writeFile(), permitting absolute-path writes or directory traversal. Crawl-result fields (title, URL, HTML) provide partial attacker influence over the JSON file contents. The repository includes README.md and ANALYSIS.md documenting the alleged vulnerable upstream path from src/server.ts through src/config.ts and src/core.ts; EVIDENCE.txt records a successful local write to /tmp/EVIDENCE-write-1.json. lab/Dockerfile builds upstream tag v1.5.1 with API_HOST=0.0.0.0 and API_PORT=3000. lab/run.sh launches that container on the host network and a Python HTTP server on port 8081 serving lab/webroot/index.html. The exploit is operational rather than an RCE: the resulting destination is suffixed with -<counter>.json and the content is JSON wrapped, constraining direct execution, but the condition can overwrite or create eligible JSON files outside the intended storage area.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated arbitrary file-write/path-traversal vulnerability in gpt-crawler through version 1.5.1. Improper validation of outputFileName in POST /crawl permits absolute-path or parent-directory traversal values, enabling overwriting of filesystem files with attacker-controlled URL-sourced content.
A high-severity arbitrary-file-write/path-traversal vulnerability in gpt-crawler through version 1.5.1. An unauthenticated network attacker can supply absolute paths or parent-directory segments in outputFileName to write or overwrite files using content fetched from attacker-controlled URLs.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.