PT-2026-6101 · Significant Gravitas · Autogpt

Sivaadityacoder

·

Published

2026-02-04

·

Updated

2026-02-17

·

CVE-2026-22038

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions AutoGPT versions prior to 0.6.46
Description AutoGPT is a platform for creating and managing AI agents to automate workflows. The Stagehand integration improperly logs API keys and authentication secrets in plaintext using logger.info() statements. This occurs within the StagehandObserveBlock, StagehandActBlock, and StagehandExtractBlock implementations, where the code calls api key.get secret value() and logs the returned value. The vulnerable code exposes sensitive information through logging mechanisms.
Recommendations Update to version 0.6.46 or later.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2026-22038
GHSA-RC89-6G7G-V5V7

Affected Products

Autogpt