PT-2023-25877 · Autogpt · Autogpt
Lukas-Eu
·
Publicado
2023-07-13
·
Atualizado
2023-07-27
·
CVE-2023-37274
CVSS v3.1
7.5
Alta
| Vetor | AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Auto-GPT versions prior to 0.4.3
Description
The issue allows for a path traversal attack, enabling the overwrite of any .py file outside the workspace directory by specifying a malicious
basename argument, such as ../../../main.py. This can be further exploited to achieve arbitrary code execution on the host running Auto-GPT. For example, overwriting autogpt/main.py can lead to code execution outside the intended docker sandbox environment when Auto-GPT is restarted.Recommendations
For versions prior to 0.4.3, update to version 0.4.3 to resolve the issue.
As a temporary workaround, consider running Auto-GPT in a virtual machine or an environment where file damage or program corruption is not critical.
Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Autogpt