CVE-2024-8156
- EPSS 1.18%
- Veröffentlicht 20.03.2025 10:09:12
- Zuletzt bearbeitet 15.10.2025 13:15:54
A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.ref` is used insecurely, allowing an attacker to inject arbitrary commands. This vulnerability affect...
CVE-2024-6091
- EPSS 0.13%
- Veröffentlicht 11.09.2024 13:15:03
- Zuletzt bearbeitet 05.08.2025 15:35:27
A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as 'whoami' and '/bin/whoami'. An attac...
CVE-2024-1880
- EPSS 0.19%
- Veröffentlicht 06.06.2024 19:15:51
- Zuletzt bearbeitet 05.08.2025 15:35:27
An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versions up to v0.5.0. The vulnerability arises from the improper neutralization of special elements used i...
CVE-2024-1881
- EPSS 0.83%
- Veröffentlicht 06.06.2024 19:15:51
- Zuletzt bearbeitet 05.08.2025 15:35:27
AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw in its shell command validation function. Specifically, the vulnerabili...
CVE-2024-1879
- EPSS 0.4%
- Veröffentlicht 06.06.2024 18:15:12
- Zuletzt bearbeitet 05.08.2025 15:35:27
A Cross-Site Request Forgery (CSRF) vulnerability in significant-gravitas/autogpt version v0.5.0 allows attackers to execute arbitrary commands on the AutoGPT server. The vulnerability stems from the lack of protections on the API endpoint receiving ...