PT-2026-6101 · Significant Gravitas · Autogpt

·

CVE-2026-22038

·

Published

2026-02-04

·

Updated

2026-02-17

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions AutoGPT versions prior to 0.6.46
Description AutoGPT is a platform for creating and managing AI agents to automate workflows. The Stagehand integration improperly logs API keys and authentication secrets in plaintext using logger.info() statements. This occurs within the StagehandObserveBlock, StagehandActBlock, and StagehandExtractBlock implementations, where the code calls api key.get secret value() and logs the returned value. The vulnerable code exposes sensitive information through logging mechanisms.
Recommendations Update to version 0.6.46 or later.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22038
GHSA-RC89-6G7G-V5V7

Affected Products

Autogpt