Записи agpt
23 опубликованных записей вендора agpt.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 43,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-285 Improper Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-770 Allocation of Resources Without Limits or Throttling2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2024-8156Эксплойта нет | Command Injection in significant-gravitas/autogptagpt · autogpt classic · CWE-77 | Критическая9,8 | — | 1,7 % | 20 мар. 2025 г. |
39Наблюдать | CVE-2024-1881Эксплойта нет | Improper Neutralization of Special Elements used in an OS Command in significant-gravitas/autogptagpt · autogpt classic · CWE-78 | Критическая9,8 | — | 1,4 % | 6 июн. 2024 г. |
39Наблюдать | CVE-2024-6091Эксплойта нет | Shell Command Denylist Bypass in significant-gravitas/autogptagpt · autogpt classic · CWE-78 | Критическая9,8 | — | 0,8 % | 11 сент. 2024 г. |
37Наблюдать | CVE-2026-26020Эксплойта нет | AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__import__)agpt · autogpt platform · CWE-285 | Критическая9,4 | — | 0,9 % | 12 февр. 2026 г. |
37Наблюдать | CVE-2025-62615Эксплойта нет | AutoGPT has SSRF vulnerability in ReadRSSFeedBlockagpt · autogpt platform · CWE-918 | Критическая9,3 | — | 0,4 % | 4 февр. 2026 г. |
37Наблюдать | CVE-2025-62616Эксплойта нет | AutoGPT has SSRF vulnerability in SendDiscordFileBlockagpt · autogpt platform · CWE-918 | Критическая9,3 | — | 0,4 % | 4 февр. 2026 г. |
36Наблюдать | CVE-2025-1040Эксплойта нет | Server-Side Template Injection (SSTI) in significant-gravitas/autogptagpt · autogpt platform · CWE-1336 | Высокая8,8 | — | 1,7 % | 20 мар. 2025 г. |
35Наблюдать | CVE-2024-1879Эксплойта нет | CSRF to RCE in significant-gravitas/autogptagpt · autogpt classic · CWE-352 | Высокая8,8 | — | 0,5 % | 6 июн. 2024 г. |
35Наблюдать | CVE-2023-37273Proof of concept | Docker escape in Auto-GPT when running from docker-compose.yml included in git repoagpt · autogpt classic · CWE-94 | Высокая8,8 | — | 0,4 % | 13 июл. 2023 г. |
34Наблюдать | CVE-2026-24780Эксплойта нет | AutoGPT is Vulnerable to RCE via Disabled Block Executionagpt · autogpt platform · CWE-94 | Высокая8,6 | — | 1,3 % | 29 янв. 2026 г. |
34Наблюдать | CVE-2025-31491Эксплойта нет | AutoGPT allows leakage of cross-domain cookies and protected headers in requests redirectagpt · autogpt platform · CWE-200 | Высокая8,6 | — | 0,5 % | 14 апр. 2025 г. |
34Наблюдать | CVE-2025-32393Эксплойта нет | AutoGPT has a DoS vulnerability in ReadRSSFeedBlockagpt · autogpt platform · CWE-770 | Высокая8,7 | — | 0,4 % | 5 февр. 2026 г. |
32Наблюдать | CVE-2026-22038Proof of concept | AutoGPT's API Keys and Secrets Logged in Plaintext in Stagehand Integration Blocksagpt · autogpt platform · CWE-532 | Высокая8,1 | — | 0,5 % | 4 февр. 2026 г. |
31Наблюдать | CVE-2024-1880Эксплойта нет | OS Command Injection in MacOS Text-To-Speech Class in significant-gravitas/autogptagpt · autogpt classic · CWE-78 | Высокая7,8 | — | 1,0 % | 6 июн. 2024 г. |
31Наблюдать | CVE-2023-37274Эксплойта нет | Python code execution sandbox escape in non-docker version in Auto-GPTagpt · autogpt classic · CWE-94 | Высокая7,8 | — | 0,4 % | 13 июл. 2023 г. |
30Наблюдать | CVE-2025-0454Эксплойта нет | SSRF Check Bypass in Requests Utility in significant-gravitas/autogptagpt · autogpt platform · CWE-918 | Высокая7,5 | — | 0,6 % | 20 мар. 2025 г. |
30Наблюдать | CVE-2025-22603Эксплойта нет | AutoGPT SSRF vulnerabilityagpt · autogpt platform · CWE-918 | Высокая7,7 | — | 0,6 % | 10 мар. 2025 г. |
30Наблюдать | CVE-2025-31490Эксплойта нет | AutoGPT allows SSRF due to DNS Rebinding in requests wrapperagpt · autogpt platform · CWE-918 | Высокая7,5 | — | 0,5 % | 14 апр. 2025 г. |
30Наблюдать | CVE-2025-53944Эксплойта нет | AutoGPT Platform Exposes Graph Execution Results via Authorization Gapagpt · autogpt platform · CWE-285 | Высокая7,7 | — | 0,5 % | 30 июл. 2025 г. |
26Наблюдать | CVE-2026-26006Эксплойта нет | Redos (Regular Expression Denial of Service) at Code Extraction Block in significant-gravitas/autogptagpt · autogpt platform · CWE-1333 | Средняя6,5 | — | 0,6 % | 10 февр. 2026 г. |
20Наблюдать | CVE-2025-32425Эксплойта нет | AutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoSagpt · autogpt platform · CWE-770 | Средняя5,1 | — | 0,2 % | 13 мая 2026 г. |
17Наблюдать | CVE-2023-37275Эксплойта нет | System logs spoofable in Auto-GPT via ANSI control sequencesagpt · autogpt classic · CWE-117 | Средняя4,3 | — | 0,4 % | 13 июл. 2023 г. |
14Наблюдать | CVE-2025-31494Эксплойта нет | AutoGPT allows cross-user sharing of node execution results through WebSockets APIagpt · autogpt platform · CWE-200 | Низкая3,5 | — | 0,4 % | 14 апр. 2025 г. |
- CVE-2024-815640В плане
Command Injection in significant-gravitas/autogpt
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %agpt · autogpt classic20 мар. 2025 г.
- CVE-2024-188139Наблюдать
Improper Neutralization of Special Elements used in an OS Command in significant-gravitas/autogpt
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %agpt · autogpt classic6 июн. 2024 г.
- CVE-2024-609139Наблюдать
Shell Command Denylist Bypass in significant-gravitas/autogpt
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %agpt · autogpt classic11 сент. 2024 г.
- CVE-2026-2602037Наблюдать
AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__import__)
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %agpt · autogpt platform12 февр. 2026 г.
- CVE-2025-6261537Наблюдать
AutoGPT has SSRF vulnerability in ReadRSSFeedBlock
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %agpt · autogpt platform4 февр. 2026 г.
- CVE-2025-6261637Наблюдать
AutoGPT has SSRF vulnerability in SendDiscordFileBlock
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %agpt · autogpt platform4 февр. 2026 г.
- CVE-2025-104036Наблюдать
Server-Side Template Injection (SSTI) in significant-gravitas/autogpt
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %agpt · autogpt platform20 мар. 2025 г.
- CVE-2024-187935Наблюдать
CSRF to RCE in significant-gravitas/autogpt
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %agpt · autogpt classic6 июн. 2024 г.
- CVE-2023-3727335Наблюдать
Docker escape in Auto-GPT when running from docker-compose.yml included in git repo
ВысокаяCVSS 8,8Proof of conceptEPSS 0 %agpt · autogpt classic13 июл. 2023 г.
- CVE-2026-2478034Наблюдать
AutoGPT is Vulnerable to RCE via Disabled Block Execution
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %agpt · autogpt platform29 янв. 2026 г.
- CVE-2025-3149134Наблюдать
AutoGPT allows leakage of cross-domain cookies and protected headers in requests redirect
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %agpt · autogpt platform14 апр. 2025 г.
- CVE-2025-3239334Наблюдать
AutoGPT has a DoS vulnerability in ReadRSSFeedBlock
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %agpt · autogpt platform5 февр. 2026 г.
- CVE-2026-2203832Наблюдать
AutoGPT's API Keys and Secrets Logged in Plaintext in Stagehand Integration Blocks
ВысокаяCVSS 8,1Proof of conceptEPSS 0 %agpt · autogpt platform4 февр. 2026 г.
- CVE-2024-188031Наблюдать
OS Command Injection in MacOS Text-To-Speech Class in significant-gravitas/autogpt
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %agpt · autogpt classic6 июн. 2024 г.
- CVE-2023-3727431Наблюдать
Python code execution sandbox escape in non-docker version in Auto-GPT
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %agpt · autogpt classic13 июл. 2023 г.
- CVE-2025-045430Наблюдать
SSRF Check Bypass in Requests Utility in significant-gravitas/autogpt
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %agpt · autogpt platform20 мар. 2025 г.
- CVE-2025-2260330Наблюдать
AutoGPT SSRF vulnerability
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %agpt · autogpt platform10 мар. 2025 г.
- CVE-2025-3149030Наблюдать
AutoGPT allows SSRF due to DNS Rebinding in requests wrapper
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %agpt · autogpt platform14 апр. 2025 г.
- CVE-2025-5394430Наблюдать
AutoGPT Platform Exposes Graph Execution Results via Authorization Gap
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %agpt · autogpt platform30 июл. 2025 г.
- CVE-2026-2600626Наблюдать
Redos (Regular Expression Denial of Service) at Code Extraction Block in significant-gravitas/autogpt
СредняяCVSS 6,5Эксплойта нетEPSS 1 %agpt · autogpt platform10 февр. 2026 г.
- CVE-2025-3242520Наблюдать
AutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoS
СредняяCVSS 5,1Эксплойта нетEPSS 0 %agpt · autogpt platform13 мая 2026 г.
- CVE-2023-3727517Наблюдать
System logs spoofable in Auto-GPT via ANSI control sequences
СредняяCVSS 4,3Эксплойта нетEPSS 0 %agpt · autogpt classic13 июл. 2023 г.
- CVE-2025-3149414Наблюдать
AutoGPT allows cross-user sharing of node execution results through WebSockets API
НизкаяCVSS 3,5Эксплойта нетEPSS 0 %agpt · autogpt platform14 апр. 2025 г.