Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Significant-Gravitas — Vulnerabilities & Security Advisories 41

Browse all 41 CVE security advisories affecting Significant-Gravitas. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Significant-Gravitas develops AI-powered cybersecurity tools, primarily focusing on automated vulnerability detection and penetration testing capabilities. Their software enables organizations to identify security flaws within applications and infrastructure without extensive manual intervention. Historical analysis of their public vulnerability database reveals a pattern of common web application security risks, including remote code execution, cross-site scripting, and broken access control issues. These defects often stem from input validation failures or improper configuration handling within their scanning engines. While no catastrophic data breaches have been publicly attributed to the company, the presence of twenty-three recorded CVEs indicates recurring challenges in securing their own development lifecycle. The incidents generally involve privilege escalation and information disclosure vectors that could allow attackers to compromise the integrity of the testing environment. This track record highlights the necessity for rigorous internal security audits even for vendors specializing in defensive technologies.

Top products by Significant-Gravitas: AutoGPT significant-gravitas/autogpt Auto-GPT
CVE ID Title CVSS Severity Published
CVE-2026-72922 AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification — AutoGPT CWE-287 8.2 High 2026-08-11
CVE-2025-32394 AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock — AutoGPT CWE-770 - - 2026-06-26
CVE-2025-32423 AutoGPT: There is a DoS vulnerability in ExtractTextInformationBlock — AutoGPT CWE-770 - - 2026-06-26
CVE-2026-56663 AutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass and internal `pg-meta` access — AutoGPT CWE-918 8.5 High 2026-06-26
CVE-2026-56823 AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping Triggering — AutoGPT CWE-284 5.4 Medium 2026-06-26
CVE-2026-33235 AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating features — AutoGPT CWE-400 7.7 High 2026-06-24
CVE-2026-55237 AutoGPT SignUp Page has DOM-Based XSS and Open Redirect — AutoGPT CWE-87 8.8 High 2026-06-18
CVE-2025-32437 AutoGPT has a DoS vulnerability in MediaDurationBlock — AutoGPT CWE-400 - - 2026-06-18
CVE-2025-32436 AutoGPT has a DoS vulnerability in AddAudioToVideoBlock — AutoGPT CWE-400 - - 2026-06-18
CVE-2025-32424 AutoGPT has a DoS vulnerability in ScreenshotWebPageBlock — AutoGPT CWE-400 - - 2026-06-18
CVE-2025-32422 AutoGPT has a DoS vulnerability in FileStoreBlock with StepThroughItemsBlock — AutoGPT CWE-400 - - 2026-06-18
CVE-2025-32392 AutoGPT has a DoS vulnerability in LoopVideoBlock — AutoGPT CWE-400 - - 2026-06-18
CVE-2026-45023 AutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/execute — AutoGPT CWE-770 5.4 Medium 2026-05-28
CVE-2026-33234 AutoGPT: SendEmailBlock's IP blocklist bypass allows SSRF via user-controlled SMTP server — AutoGPT CWE-918 5.0 Medium 2026-05-19
CVE-2026-33233 AutoGPT Platform: Remote Code Execution via Unsafe Pickle Deserialization of Redis Cache Entries — AutoGPT CWE-502 7.6 High 2026-05-19
CVE-2026-33232 AutoGPT: Unauthenticated DoS via Disk Space Exhaustion — AutoGPT CWE-459 7.5 High 2026-05-19
CVE-2026-30950 AutoGPT has Authenticated Session Hijacking via IDOR — AutoGPT CWE-862 7.1 High 2026-05-18
CVE-2025-32425 AutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoS — AutoGPT CWE-770 - - 2026-05-13
CVE-2026-26020 AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__import__) — AutoGPT CWE-285 8.8AI High AI 2026-02-12
CVE-2026-26006 Redos (Regular Expression Denial of Service) at Code Extraction Block in significant-gravitas/autogpt — AutoGPT CWE-1333 6.5 Medium 2026-02-10
CVE-2025-32393 AutoGPT has a DoS vulnerability in ReadRSSFeedBlock — AutoGPT CWE-770 6.5AI Medium AI 2026-02-05
CVE-2025-62616 AutoGPT has SSRF vulnerability in SendDiscordFileBlock — AutoGPT CWE-918 8.1AI High AI 2026-02-04
CVE-2025-62615 AutoGPT has SSRF vulnerability in ReadRSSFeedBlock — AutoGPT CWE-918 9.1AI Critical AI 2026-02-04
CVE-2026-22038 AutoGPT's API Keys and Secrets Logged in Plaintext in Stagehand Integration Blocks — AutoGPT CWE-532 8.1 High 2026-02-04
CVE-2026-24780 AutoGPT is Vulnerable to RCE via Disabled Block Execution — AutoGPT CWE-863 8.8AI High AI 2026-01-29
CVE-2025-53944 AutoGPT Platform Exposes Graph Execution Results via Authorization Gap — AutoGPT CWE-285 7.7 High 2025-07-30
CVE-2025-31494 AutoGPT allows cross-user sharing of node execution results through WebSockets API — AutoGPT CWE-200 3.5 Low 2025-04-14
CVE-2025-31491 AutoGPT allows leakage of cross-domain cookies and protected headers in requests redirect — AutoGPT CWE-200 8.6 High 2025-04-14
CVE-2025-31490 AutoGPT allows SSRF due to DNS Rebinding in requests wrapper — AutoGPT CWE-918 7.5 High 2025-04-14
CVE-2024-10457 SSRF Vulnerabilities in significant-gravitas/autogpt — significant-gravitas/autogpt CWE-918 9.1 - 2025-03-20

This page lists every published CVE security advisory associated with Significant-Gravitas. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.