Auto-GPT是Significant Gravitas开源的一个人工智能软件代理程序。 Auto-GPT 0.5.0版本至5.1.0之前版本存在操作系统命令注入漏洞,该漏洞源于操作系统命令中使用的特殊元素的不当中和,从而导致攻击者可绕过限制执行任意shell命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| significant-gravitas | significant-gravitas/autogpt | unspecified ~ 5.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-1879 | CSRF to RCE in significant-gravitas/autogpt | |
| CVE-2024-1880 | OS Command Injection in MacOS Text-To-Speech Class in significant-gravitas/autogpt |
No comments yet