Autogpt
This hub aggregates every CVE we track for Autogpt, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
25
CVEs tracked
3
Critical
15
High
0
In CISA KEV
Severity distribution
HIGH15MEDIUM6CRITICAL3LOW1
Monthly trend
1
0
0
0
0
0
1
3
0
0
1
0
0
0
0
0
1
6
0
0
6
4
0
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Autogpt.
- CVE-2026-72922AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification8.2
- CVE-2026-56663AutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass and internal `pg-meta` access8.5
- CVE-2026-56823AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping Triggering5.4
- CVE-2026-33235AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating features7.7
- CVE-2026-55237AutoGPT SignUp Page has DOM-Based XSS and Open Redirect8.8
- CVE-2026-45023AutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/execute5.4
- CVE-2026-33234AutoGPT: SendEmailBlock's IP blocklist bypass allows SSRF via user-controlled SMTP server5.0
- CVE-2026-33233AutoGPT Platform: Remote Code Execution via Unsafe Pickle Deserialization of Redis Cache Entries7.6
- CVE-2026-33232AutoGPT: Unauthenticated DoS via Disk Space Exhaustion7.5
- CVE-2026-30950AutoGPT has Authenticated Session Hijacking via IDOR7.1
- CVE-2025-32425AutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoS5.5
- CVE-2026-26020AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__import__)8.8
- CVE-2026-26006Redos (Regular Expression Denial of Service) at Code Extraction Block in significant-gravitas/autogpt6.5
- CVE-2025-32393AutoGPT has a DoS vulnerability in ReadRSSFeedBlock6.5
- CVE-2025-62616AutoGPT has SSRF vulnerability in SendDiscordFileBlock9.8
Product normalization is registry-driven with AI assist and human review. How it works