PT-2026-5938 · Autogpt · Autogpt
CVE-2025-62616
·
Publicado
2026-02-04
·
Atualizado
2026-02-05
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AutoGPT versions prior to 0.6.34
Description
AutoGPT is a platform for creating, deploying, and managing continuous artificial intelligence agents to automate complex workflows. A Server-Side Request Forgery (SSRF) issue exists in the SendDiscordFileBlock function due to the use of the
aiohttp.ClientSession().get function without proper input validation of the URL. This allows an attacker to potentially make requests to unintended locations.Recommendations
Update to version 0.6.34 or later.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Autogpt