PT-2023-25878 · Autogpt · Autogpt

Lukas-Eu

·

Publicado

2023-07-13

·

Atualizado

2023-07-27

·

CVE-2023-37275

CVSS v3.1

3.1

Baixa

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Auto-GPT versions prior to 0.4.3
Description The issue concerns the Auto-GPT command line UI, which uses color-coded print statements to signify different types of system messages. Before the patch, a malicious external resource could cause misleading messages to be printed to the console by getting the LLM to regurgitate JSON encoded ANSI escape sequences, such as u001b[. These escape sequences were JSON decoded and printed to the console as part of the model's "thinking process".
Recommendations For versions prior to 0.4.3, update to release version 0.4.3 to resolve the issue. As a temporary workaround, consider restricting the use of external resources that may cause misleading messages to be printed to the console until the patch is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37275
GHSA-R7F7-QRRV-3FJH

Produtos afetados

Autogpt