PT-2026-7904 · Autogpt · Autogpt

222N5

·

Publicado

2026-02-12

·

Atualizado

2026-03-14

·

CVE-2026-26020

CVSS v4.0

9.4

Crítica

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions AutoGPT versions prior to 0.6.48
Description AutoGPT is a platform for creating and managing AI agents to automate workflows. An authenticated user could achieve Remote Code Execution (RCE) on the backend server. This occurred because the BlockInstallationBlock, a tool for writing and importing Python code, was marked as disabled but graph validation did not enforce this setting. By including the block as a node within a graph, users bypassed the restriction. The vulnerable component is the BlockInstallationBlock.
Recommendations Update to version 0.6.48 or later.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26020
GHSA-4CRW-9P35-9X54

Produtos afetados

Autogpt