PT-2026-5937 · Autogpt · Autogpt

Published

2026-02-04

·

Updated

2026-03-03

·

CVE-2025-62615

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AutoGPT versions prior to 0.6.34
Description AutoGPT is a platform for creating and managing AI agents to automate workflows. A Server-Side Request Forgery (SSRF) issue exists in the RSSFeedBlock component due to the direct use of urllib.request.urlopen to access URLs without input validation. This allows an attacker to potentially make requests to unintended locations. The vulnerable code does not filter the input URL before using it.
Recommendations Update to version 0.6.34 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-62615
GHSA-R55V-Q5PC-J57F

Affected Products

Autogpt