PT-2025-31393 · Autogpt · Autogpt
Geckosecurity
+2
·
Published
2025-07-30
·
Updated
2025-08-25
·
CVE-2025-53944
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AutoGPT versions prior to 0.6.16
Description
AutoGPT is a platform for creating, deploying, and managing continuous artificial intelligence agents. The external API’s
get graph execution results endpoint has an authorization bypass. While the API correctly validates user access to the graph id parameter, it fails to verify ownership of the graph exec id parameter. This allows authenticated users to access any execution results by providing arbitrary execution IDs. The internal API implements proper validation for both parameters.Recommendations
Update AutoGPT to version 0.6.16 or later.
Exploit
Fix
Improper Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Autogpt