PT-2026-5937 · Autogpt · Autogpt
Published
2026-02-04
·
Updated
2026-03-03
·
CVE-2025-62615
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AutoGPT versions prior to 0.6.34
Description
AutoGPT is a platform for creating and managing AI agents to automate workflows. A Server-Side Request Forgery (SSRF) issue exists in the RSSFeedBlock component due to the direct use of
urllib.request.urlopen to access URLs without input validation. This allows an attacker to potentially make requests to unintended locations. The vulnerable code does not filter the input URL before using it.Recommendations
Update to version 0.6.34 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autogpt