Auto-GPT是Significant Gravitas开源的一个人工智能软件代理程序。 Auto-GPT 0.4.3之前版本存在代码注入漏洞,该漏洞源于位于存储库根目录中的 docker-compose.yml 文件将自身安装到 docker 容器中,且没有写保护,如果通过和命令执行恶意自定义 python 代码,它可以覆盖 docker-compose.yml 文件并在下次 Auto-GPT 启动时来获得对主机系统的控制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Significant-Gravitas | Auto-GPT | < 0.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Site containing info useful for demonstrate CVE-2023-37273 | https://github.com/gdesantis01/instructions-summarizing | POC Details |
| CVE-2023-37274 | 7.6 HIGH | Python code execution sandbox escape in non-docker version in Auto-GPT |
| CVE-2023-37275 | 3.1 LOW | System logs spoofable in Auto-GPT via ANSI control sequences |
No comments yet