Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 1.3% | — | Agpt Autogpt Platform | 29/1/2026 | 17/6/2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both main web API and external API) allow executing blocks by UUID without checking the… | |
| Analizada | Alta (7.7) | 0.46% | — | Agpt Autogpt Platform | 30/7/2025 | 17/6/2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external API's get_graph_execution_results endpoint has an authorization bypass vulnerability. While it correctly validates user access to the graph_id, it fails to verify… | |
| Analizada | Baja (3.5) | 0.39% | — | Agpt Autogpt Platform | 15/4/2025 | 17/6/2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. The AutoGPT Platform's WebSocket API transmitted node execution updates to subscribers based on the graph_id+graph_version. Additionally, there was no check prohibiting users… | |
| Analizada | Alta (8.6) | 0.47% | — | Agpt Autogpt Platform | 15/4/2025 | 17/6/2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows of leakage of cross-domain cookies and protected headers in requests redirect. AutoGPT uses a wrapper around the requests python library,… | |
| Analizada | Alta (7.5) | 0.49% | — | Agpt Autogpt Platform | 14/4/2025 | 17/6/2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows SSRF due to DNS Rebinding in requests wrapper. AutoGPT is built with a wrapper around Python's requests library, hardening the application… | |
| Modificada | Alta (8.8) | 1.7% | — | Agpt Autogpt Platform | 20/3/2025 | 17/6/2026 | AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the improper handling of user-supplied format strings in the `AgentOutputBlock` implementation, where malicious input is passed to the Jinja2… | |
| Analizada | Alta (7.5) | 0.57% | — | Agpt Autogpt Platform | 20/3/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. The vulnerability arises due to a hostname confusion between the `urlparse` function from the `urllib.parse` library and the `requests` library. A malicious user can… | |
| Modificada | Crítica (9.8) | 1.7% | — | Agpt Autogpt Classic | 20/3/2025 | 17/6/2026 | A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.ref` is used insecurely, allowing an attacker to inject arbitrary commands. This vulnerability affects versions up to and including the latest version. An attacker can… | |
| Aplazada | Media (6.5) | 0.56% | — | Significant-gravitas AutogptAI | 20/3/2025 | 17/6/2026 | Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt repository, specifically in the GitHub Integration and Web Search blocks. These vulnerabilities affect version agpt-platform-beta-v0.1.1. The issues arise when block inputs are controlled by untrusted… | |
| Analizada | Alta (7.7) | 0.58% | — | Agpt Autogpt Platform | 10/3/2025 | 17/6/2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Versions prior to autogpt-platform-beta-v0.4.2 contains a server-side request forgery (SSRF) vulnerability inside component (or block) `Send Web Request`. The root cause is… | |
| Analizada | Crítica (9.8) | 0.82% | — | Agpt Autogpt Classic | 11/9/2024 | 17/6/2026 | A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as 'whoami' and '/bin/whoami'. An attacker can circumvent this restriction by executing commands with a… | |
| Modificada | Crítica (9.8) | 1.4% | — | Agpt Autogpt Classic | 6/6/2024 | 17/6/2026 | AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw in its shell command validation function. Specifically, the vulnerability exists in versions v0.5.0 up to but not including 5.1.0. The issue… | |
| Modificada | Alta (7.8) | 1.0% | — | Agpt Autogpt Classic | 6/6/2024 | 17/6/2026 | An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versions up to v0.5.0. The vulnerability arises from the improper neutralization of special elements used in an OS command within the `_speech` method of the MacOSTTS class.… | |
| Modificada | Alta (8.8) | 0.52% | — | Agpt Autogpt Classic | 6/6/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in significant-gravitas/autogpt version v0.5.0 allows attackers to execute arbitrary commands on the AutoGPT server. The vulnerability stems from the lack of protections on the API endpoint receiving instructions, enabling an attacker to direct a user running AutoGPT… | |
| Analizada | Media (4.3) | 0.44% | — | Agpt Autogpt Classic | 13/7/2023 | 17/6/2026 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. The Auto-GPT command line UI makes heavy use of color-coded print statements to signify different types of system messages to the user, including messages that are crucial for the user to review and control… | |
| Analizada | Alta (7.8) | 0.35% | — | Agpt Autogpt Classic | 13/7/2023 | 17/6/2026 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-GPT is executed directly on the host system via the provided run.sh or run.bat files, custom Python code execution is sandboxed using a temporary dedicated docker container which should not have… | |
| Analizada | Alta (8.8) | 0.36% | — | Agpt Autogpt Classic | 13/7/2023 | 17/6/2026 | Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Auto-GPT version prior to 0.4.3 by cloning the git repo and executing `docker compose run auto-gpt` in the repo root uses a different docker-compose.yml file from the one suggested in the official… |