Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass and internal `pg-meta` access
Vulnerability Description
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authenticated user can bypass the SSRF / private-IP protections in SendWebRequestBlock and reach internal network services. _is_ip_blocked() in backend/backend/util/request.py does not normalize IPv4-mapped IPv6 addresses before checking resolved IPs against the blocked IPv4 ranges, and does not block special-use ranges such as 100.64.0.0/10 (CGNAT, RFC 6598). A hostname that resolves to an IPv4-mapped IPv6 address therefore passes validation and the request reaches the embedded internal IPv4 endpoint. This affects all AutoGPT Platform deployments. This vulnerability is fixed in 0.6.52.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Significant-Gravitas AutoGPT 服务端请求伪造漏洞
Vulnerability Description
Significant-Gravitas AutoGPT是Significant-Gravitas的人工智能软件。 Significant-Gravitas AutoGPT 0.6.52之前版本存在服务端请求伪造漏洞,该漏洞源于_is_ip_blocked()函数未正确规范化IPv4映射IPv6地址且未阻止特殊用途范围,可能导致经过身份验证的攻击者绕过SSRF/私有IP保护,访问内部网络服务。
CVSS Information
N/A
Vulnerability Type
N/A