CVE-2025-53944

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-53944
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-53944.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-53944
Related
  • GHSA-x77j-qg2x-fgg6
Published
2025-07-30T15:15:35Z
Modified
2025-07-31T20:50:57.600585Z
Summary
[none]
Details

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external API's getgraphexecutionresults endpoint has an authorization bypass vulnerability. While it correctly validates user access to the graphid, it fails to verify ownership of the graphexecid parameter, allowing authenticated users to access any execution results by providing arbitrary execution IDs. The internal API implements proper validation for both parameters. This is fixed in v0.6.16.

References

Affected packages

Git / github.com/significant-gravitas/autogpt

Affected ranges

Type
GIT
Repo
https://github.com/significant-gravitas/autogpt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

agbenchmark-v0.*

agbenchmark-v0.0.10

agpt-platform-beta-v0.*

agpt-platform-beta-v0.1.0
agpt-platform-beta-v0.1.1
agpt-platform-beta-v0.2.0

autogpt-platform-beta-v0.*

autogpt-platform-beta-v0.2.1
autogpt-platform-beta-v0.2.2
autogpt-platform-beta-v0.3.0
autogpt-platform-beta-v0.3.1
autogpt-platform-beta-v0.3.2
autogpt-platform-beta-v0.3.3
autogpt-platform-beta-v0.3.4
autogpt-platform-beta-v0.4.0
autogpt-platform-beta-v0.4.1
autogpt-platform-beta-v0.4.10
autogpt-platform-beta-v0.4.11
autogpt-platform-beta-v0.4.2
autogpt-platform-beta-v0.4.3
autogpt-platform-beta-v0.4.4
autogpt-platform-beta-v0.4.5
autogpt-platform-beta-v0.4.6
autogpt-platform-beta-v0.4.7
autogpt-platform-beta-v0.4.8
autogpt-platform-beta-v0.4.9
autogpt-platform-beta-v0.5.0
autogpt-platform-beta-v0.5.1
autogpt-platform-beta-v0.6.0
autogpt-platform-beta-v0.6.1
autogpt-platform-beta-v0.6.10
autogpt-platform-beta-v0.6.11
autogpt-platform-beta-v0.6.12
autogpt-platform-beta-v0.6.13
autogpt-platform-beta-v0.6.14
autogpt-platform-beta-v0.6.15
autogpt-platform-beta-v0.6.2
autogpt-platform-beta-v0.6.3
autogpt-platform-beta-v0.6.4
autogpt-platform-beta-v0.6.5
autogpt-platform-beta-v0.6.6
autogpt-platform-beta-v0.6.7
autogpt-platform-beta-v0.6.8
autogpt-platform-beta-v0.6.9

v0.*

v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.2.0
v0.2.1
v0.2.2
v0.3.0
v0.3.1
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.3-alpha
v0.4.4
v0.4.5