Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

AutoGPT — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in AutoGPT, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for AutoGPT, focusing specifically on its implementation of common software weaknesses. The collection comprises security advisories and flaw reports spanning from the project's inception through the latest release, including issues identified by the maintainers and the broader security community. Readers can track the vendor's advisory history, analyze specific weakness categories such as command injection or access control flaws, and review the product's cumulative vulnerability record to identify recurring patterns. The data is organized to facilitate the correlation of historical incidents with current release notes, allowing analysts to assess whether known weaknesses have been addressed in subsequent updates. No specific CVE identifiers are listed in this summary; instead, the emphasis is placed on the structural evolution of the codebase and the mitigation strategies employed by the development team over time.

Vendor: Significant-Gravitas

CVE ID Title CVSS Severity Published
CVE-2026-72922 AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification CWE-287 8.2 High 2026-08-11
CVE-2025-32394 AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock CWE-770 - - 2026-06-26
CVE-2025-32423 AutoGPT: There is a DoS vulnerability in ExtractTextInformationBlock CWE-770 - - 2026-06-26
CVE-2026-56663 AutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass and internal `pg-meta` access CWE-918 8.5 High 2026-06-26
CVE-2026-56823 AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping Triggering CWE-284 5.4 Medium 2026-06-26
CVE-2026-33235 AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating features CWE-400 7.7 High 2026-06-24
CVE-2026-55237 AutoGPT SignUp Page has DOM-Based XSS and Open Redirect CWE-87 8.8 High 2026-06-18
CVE-2025-32437 AutoGPT has a DoS vulnerability in MediaDurationBlock CWE-400 - - 2026-06-18
CVE-2025-32436 AutoGPT has a DoS vulnerability in AddAudioToVideoBlock CWE-400 - - 2026-06-18
CVE-2025-32424 AutoGPT has a DoS vulnerability in ScreenshotWebPageBlock CWE-400 - - 2026-06-18
CVE-2025-32422 AutoGPT has a DoS vulnerability in FileStoreBlock with StepThroughItemsBlock CWE-400 - - 2026-06-18
CVE-2025-32392 AutoGPT has a DoS vulnerability in LoopVideoBlock CWE-400 - - 2026-06-18
CVE-2026-45023 AutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/execute CWE-770 5.4 Medium 2026-05-28
CVE-2026-33234 AutoGPT: SendEmailBlock's IP blocklist bypass allows SSRF via user-controlled SMTP server CWE-918 5.0 Medium 2026-05-19
CVE-2026-33233 AutoGPT Platform: Remote Code Execution via Unsafe Pickle Deserialization of Redis Cache Entries CWE-502 7.6 High 2026-05-19
CVE-2026-33232 AutoGPT: Unauthenticated DoS via Disk Space Exhaustion CWE-459 7.5 High 2026-05-19
CVE-2026-30950 AutoGPT has Authenticated Session Hijacking via IDOR CWE-862 7.1 High 2026-05-18
CVE-2025-32425 AutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoS CWE-770 - - 2026-05-13
CVE-2025-41023 Authentication bypass in AutoGPT de Thesamur CWE-287 9.8AI Critical AI 2026-02-19
CVE-2026-26020 AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__import__) CWE-285 8.8AI High AI 2026-02-12
CVE-2026-26006 Redos (Regular Expression Denial of Service) at Code Extraction Block in significant-gravitas/autogpt CWE-1333 6.5 Medium 2026-02-10
CVE-2025-32393 AutoGPT has a DoS vulnerability in ReadRSSFeedBlock CWE-770 6.5AI Medium AI 2026-02-05
CVE-2025-62616 AutoGPT has SSRF vulnerability in SendDiscordFileBlock CWE-918 8.1AI High AI 2026-02-04
CVE-2025-62615 AutoGPT has SSRF vulnerability in ReadRSSFeedBlock CWE-918 9.1AI Critical AI 2026-02-04
CVE-2026-22038 AutoGPT's API Keys and Secrets Logged in Plaintext in Stagehand Integration Blocks CWE-532 8.1 High 2026-02-04
CVE-2026-24780 AutoGPT is Vulnerable to RCE via Disabled Block Execution CWE-863 8.8AI High AI 2026-01-29
CVE-2025-53944 AutoGPT Platform Exposes Graph Execution Results via Authorization Gap CWE-285 7.7 High 2025-07-30
CVE-2025-31494 AutoGPT allows cross-user sharing of node execution results through WebSockets API CWE-200 3.5 Low 2025-04-14
CVE-2025-31491 AutoGPT allows leakage of cross-domain cookies and protected headers in requests redirect CWE-200 8.6 High 2025-04-14
CVE-2025-31490 AutoGPT allows SSRF due to DNS Rebinding in requests wrapper CWE-918 7.5 High 2025-04-14

All 31 known CVE vulnerabilities affecting AutoGPT with full Chinese analysis, references, and POCs where available.