PT-2024-10397 · Significant Gravitas · Autogpt
Published
2024-09-11
·
Updated
2025-08-05
·
CVE-2024-6091
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
significant-gravitas/autogpt version 0.5.1
Description
A vulnerability in significant-gravitas/autogpt allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as
whoami and /bin/whoami. An attacker can circumvent this restriction by executing commands with a modified path, such as /bin/./whoami, which is not recognized by the denylist. Over 166,000 projects are at risk due to this vulnerability.Recommendations
As a temporary workaround, consider disabling the execution of shell commands until a patch is available. Restrict access to the denylist settings to minimize the risk of exploitation. Avoid using the denylist to block specific commands, as an attacker can modify the command path to bypass the restriction. Update to a newer version that contains a fix for this vulnerability, if available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autogpt