PT-2026-6101 · Significant Gravitas · Autogpt
Sivaadityacoder
·
Published
2026-02-04
·
Updated
2026-02-17
·
CVE-2026-22038
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
AutoGPT versions prior to 0.6.46
Description
AutoGPT is a platform for creating and managing AI agents to automate workflows. The Stagehand integration improperly logs API keys and authentication secrets in plaintext using
logger.info() statements. This occurs within the StagehandObserveBlock, StagehandActBlock, and StagehandExtractBlock implementations, where the code calls api key.get secret value() and logs the returned value. The vulnerable code exposes sensitive information through logging mechanisms.Recommendations
Update to version 0.6.46 or later.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autogpt