PT-2026-5938 · Autogpt · Autogpt
Published
2026-02-04
·
Updated
2026-02-05
·
CVE-2025-62616
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AutoGPT versions prior to 0.6.34
Description
AutoGPT is a platform for creating, deploying, and managing continuous artificial intelligence agents to automate complex workflows. A Server-Side Request Forgery (SSRF) issue exists in the SendDiscordFileBlock function due to the use of the
aiohttp.ClientSession().get function without proper input validation of the URL. This allows an attacker to potentially make requests to unintended locations.Recommendations
Update to version 0.6.34 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autogpt