CVE-2025-53944
- EPSS 0.08%
- Veröffentlicht 30.07.2025 14:28:36
- Zuletzt bearbeitet 05.08.2025 14:40:34
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external API's get_graph_execution_results endpoint has an authorization bypass vulnerability. While it correct...
CVE-2025-31494
- EPSS 0.04%
- Veröffentlicht 14.04.2025 23:21:10
- Zuletzt bearbeitet 25.08.2025 02:23:37
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. The AutoGPT Platform's WebSocket API transmitted node execution updates to subscribers based on the graph...
CVE-2025-31491
- EPSS 0.07%
- Veröffentlicht 14.04.2025 23:15:56
- Zuletzt bearbeitet 05.08.2025 17:04:15
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows of leakage of cross-domain cookies and protected headers in requests redir...
CVE-2025-31490
- EPSS 0.07%
- Veröffentlicht 14.04.2025 23:15:21
- Zuletzt bearbeitet 05.08.2025 17:04:28
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows SSRF due to DNS Rebinding in requests wrapper. AutoGPT is built with a wra...
CVE-2025-0454
- EPSS 0.08%
- Veröffentlicht 20.03.2025 10:11:30
- Zuletzt bearbeitet 05.08.2025 17:04:05
A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. The vulnerability arises due to a hostname confusion between the `urlparse` function from the `urllib....
CVE-2025-1040
- EPSS 1.61%
- Veröffentlicht 20.03.2025 10:11:05
- Zuletzt bearbeitet 15.10.2025 13:16:01
AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the improper handling of user-supplied format strings in the `AgentOutputBlock`...