PT-2026-5937 · Autogpt · Autogpt
CVE-2025-62615
·
Publicado
2026-02-04
·
Atualizado
2026-03-03
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AutoGPT versions prior to 0.6.34
Description
AutoGPT is a platform for creating and managing AI agents to automate workflows. A Server-Side Request Forgery (SSRF) issue exists in the RSSFeedBlock component due to the direct use of
urllib.request.urlopen to access URLs without input validation. This allows an attacker to potentially make requests to unintended locations. The vulnerable code does not filter the input URL before using it.Recommendations
Update to version 0.6.34 or later.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Autogpt