CVE-2026-82286 affects gpt-crawler through version 1.5.1, a tool by BuilderIO. The vulnerability exists in the POST /crawl endpoint, which fails to validate the outputFileName parameter. Unauthenticated attackers can exploit this flaw to write arbitrary files to any filesystem path by supplying absolute paths or parent-directory traversal segments. The file content is sourced from attacker-controlled URLs, enabling overwrite of existing critical files. No authentication is required to exploit this vulnerability, significantly raising its risk profile. The issue has been documented in a GitHub issue and detailed in a VulnCheck advisory. Affected parties are advised to update or apply mitigations immediately.