PT-2025-31393 · Autogpt · Autogpt

Geckosecurity

+2

·

Published

2025-07-30

·

Updated

2025-08-25

·

CVE-2025-53944

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AutoGPT versions prior to 0.6.16
Description AutoGPT is a platform for creating, deploying, and managing continuous artificial intelligence agents. The external API’s get graph execution results endpoint has an authorization bypass. While the API correctly validates user access to the graph id parameter, it fails to verify ownership of the graph exec id parameter. This allows authenticated users to access any execution results by providing arbitrary execution IDs. The internal API implements proper validation for both parameters.
Recommendations Update AutoGPT to version 0.6.16 or later.

Exploit

Fix

Improper Authorization

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-53944
GHSA-X77J-QG2X-FGG6

Affected Products

Autogpt