漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
Vulnerability Description
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), which is passed to `router.push`. An attacker can craft a malicious link that, when opened by an authenticated user, performs a client-side redirect and executes arbitrary JavaScript in the context of their browser. This could lead to credential theft, internal network pivoting, and unauthorized actions performed on behalf of the victim. Version 0.6.62 patches the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
Vulnerability Type
替代XSS语法转义处理不恰当
Vulnerability Title
Significant-Gravitas AutoGPT 输入验证错误漏洞
Vulnerability Description
Significant-Gravitas AutoGPT是Significant-Gravitas的人工智能软件。 Significant-Gravitas AutoGPT 0.6.62之前版本存在输入验证错误漏洞,该漏洞源于对URL参数`next`信任不当,可能导致攻击者构造恶意链接,当经过身份验证的用户打开后,在浏览器环境中执行客户端重定向和任意JavaScript,从而可能导致凭据窃取、内部网络横向移动以及代表受害者执行未授权操作。
CVSS Information
N/A
Vulnerability Type
N/A