PT-2026-50695 · Autogpt · Autogpt

CVE-2025-32437

·

Published

2026-06-18

·

Updated

2026-06-18

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AutoGPT versions prior to 0.6.63
Description AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. The MediaDurationBlock function downloads and stores videos in a temporary directory without deleting them before all nodes are completed. Furthermore, MediaDurationBlock does not limit the disk space consumed in the current working directory and fails to delete the video after outputting the result. Because the StepThroughItemsBlock function can iterate MediaDurationBlock multiple times without a limit on the number of loops, a malicious user can trigger numerous web page screenshots to exhaust disk space, resulting in a Denial of Service (DoS), which is a condition where a system becomes unavailable to its intended users.
Recommendations Update to version 0.6.63.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32437
GHSA-RG6V-M9X9-7WF9

Affected Products

Autogpt