PT-2026-6101 · Significant Gravitas · Autogpt
Sivaadityacoder
·
Publicado
2026-02-04
·
Atualizado
2026-02-17
·
CVE-2026-22038
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
AutoGPT versions prior to 0.6.46
Description
AutoGPT is a platform for creating and managing AI agents to automate workflows. The Stagehand integration improperly logs API keys and authentication secrets in plaintext using
logger.info() statements. This occurs within the StagehandObserveBlock, StagehandActBlock, and StagehandExtractBlock implementations, where the code calls api key.get secret value() and logs the returned value. The vulnerable code exposes sensitive information through logging mechanisms.Recommendations
Update to version 0.6.46 or later.
Exploit
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Autogpt