VendorsAgptautogpt_platformall versions
Vulnerabilities

Agpt Determinist Ltd AutoGPT Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2025-62615
AutoGPT has SSRF vulnerability in ReadRSSFeedBlock
Published 2026-02-04 · Analyzed
9.8EPSS 0.004
CVE-2025-62616
AutoGPT has SSRF vulnerability in SendDiscordFileBlock
Published 2026-02-04 · Analyzed
9.8EPSS 0.004
CVE-2026-26020
AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__import__)
Published 2026-02-12 · Analyzed
9.4EPSS 0.009
CVE-2025-1040
Server-Side Template Injection (SSTI) in significant-gravitas/autogpt
Published 2025-03-20 · Modified
8.8EPSS 0.017
CVE-2026-24780
AutoGPT is Vulnerable to RCE via Disabled Block Execution
Published 2026-01-29 · Analyzed
8.8EPSS 0.012
CVE-2025-32393
AutoGPT has a DoS vulnerability in ReadRSSFeedBlock
Published 2026-02-05 · Analyzed
8.7EPSS 0.004
CVE-2025-31491
AutoGPT allows leakage of cross-domain cookies and protected headers in requests redirect
Published 2025-04-14 · Analyzed
8.6EPSS 0.005
CVE-2025-22603
AutoGPT SSRF vulnerability
Published 2025-03-10 · Analyzed
8.1EPSS 0.006
CVE-2026-22038
AutoGPT's API Keys and Secrets Logged in Plaintext in Stagehand Integration Blocks
Published 2026-02-04 · Analyzed
8.1EPSS 0.005
CVE-2025-53944
AutoGPT Platform Exposes Graph Execution Results via Authorization Gap
Published 2025-07-30 · Analyzed
7.7EPSS 0.004
CVE-2025-0454
SSRF Check Bypass in Requests Utility in significant-gravitas/autogpt
Published 2025-03-20 · Analyzed
7.5EPSS 0.006
CVE-2025-31490
AutoGPT allows SSRF due to DNS Rebinding in requests wrapper
Published 2025-04-14 · Analyzed
7.5EPSS 0.005
CVE-2026-26006
Redos (Regular Expression Denial of Service) at Code Extraction Block in significant-gravitas/autogpt
Published 2026-02-10 · Analyzed
6.5EPSS 0.006
CVE-2025-32425
AutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoS
Published 2026-05-13 · Analyzed
5.5EPSS 0.002
CVE-2025-31494
AutoGPT allows cross-user sharing of node execution results through WebSockets API
Published 2025-04-14 · Analyzed
3.5EPSS 0.004