PT-2025-12320 · Jinja2+1 · Jinja2+1

CVE-2025-1040

·

Publicado

2025-03-20

·

Atualizado

2025-08-05

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AutoGPT versions 0.3.4 and earlier
Description AutoGPT versions 0.3.4 and earlier are susceptible to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). This issue stems from the inadequate handling of user-supplied format strings within the AgentOutputBlock implementation, where malicious input is passed to the Jinja2 templating engine without sufficient security measures. Attackers can leverage this flaw to execute arbitrary commands on the host system.
Recommendations Update AutoGPT to version 0.4.0 or later.

Exploit

Correção

RCE

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-1040

Produtos afetados

Autogpt
Jinja2