Repository navigation
Security: Significant-Gravitas/AutoGPT
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Webhook provider path confusion bypasses generic webhook secret verificationGHSA-349p-3c3r-8mjr published
Aug 5, 2026 by kczeHigh -
Preset creation can bind a foreign webhook, enabling known-ID forged victim webhook executions and exposing its signing secretGHSA-4m2w-qfr5-9f3v published
Jul 21, 2026 by PwutsModerate -
IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping TriggeringGHSA-rq9m-xvc7-v9h6 published
Jun 26, 2026 by kczeModerate -
Hardcoded Default Fernet Encryption Key Exposes All Stored OAuth CredentialsGHSA-57mf-wqwq-6g6x published
Oct 5, 2026 by kczeHigh -
Hardcoded Default JWT Secret Enables Complete Authentication BypassGHSA-24q6-6h89-f9p7 published
Oct 5, 2026 by kczeCritical -
AutoGPT Classic: SSRF in llamafile setup script via unvalidated download URL and redirectsGHSA-vm4v-5hgj-rq77 published
Jul 14, 2026 by kczeHigh -
Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/executeGHSA-8pjg-mfqm-vrhr published
May 11, 2026 by kczeModerate -
AutoGPT Classic: HTTP client domain allowlist bypass via userinfo and backslash URL tricksGHSA-xxpr-ccx5-48mf published
Jul 14, 2026 by kczeModerate -
AutoGPT Classic: SSRF in web fetch commands via missing internal/private address validationGHSA-vj3m-g4cv-8j93 published
Jul 14, 2026 by kczeHigh -
AutoGPT Classic: GitHub credentials sent to arbitrary hosts via clone_repository URLGHSA-c543-3829-f27q published
Jul 14, 2026 by kczeHigh