Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Agpt

First CVE: Jul 13, 2023Active for: 3 yearsTotal CVEs: 23
45.1
VTI Score
High

Agpt maintains a modestly represented but prominent vulnerability footprint across its AutoGPT platform and related automation products, which sit at the intersection of code generation, command execution, and external service integration. The vendor's vulnerabilities skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the inherent risks of dynamically generated and executed code. The exposure recurs through weakness classes including server-side request forgery, code injection, OS command injection, resource exhaustion, and sensitive information disclosure—structural hazards that arise from the automation and agent-execution model underlying these tools. Defenders should prioritize patching releases from this vendor, particularly in environments where AutoGPT instances have network or system access. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
2.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Agpt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 13, 2023
3 years ago
Most Recent CVE
May 13, 2026
72 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-62615CRITICAL
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6
Feb 4, 20269.833NONO
CVE-2026-26020HIGH
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.48, an authenticated u
Feb 12, 20268.832NONO
CVE-2026-24780HIGH
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6
Jan 29, 20268.831NONO
CVE-2024-6091CRITICAL
A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to
Sep 11, 20249.831NONO
CVE-2025-62616CRITICAL
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6
Feb 4, 20269.830NONO
CVE-2025-1040HIGH
AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the impro
Mar 20, 20258.827NONO
CVE-2024-8156CRITICAL
A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.ref` is used insecurely, allowi
Mar 20, 20259.827NONO
CVE-2024-1881CRITICAL
AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw i
Jun 6, 20249.827NONO
CVE-2026-22038HIGH
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6
Feb 4, 20268.126NONO
CVE-2025-53944HIGH
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external API's get_graph_execution_result
Jul 30, 20257.726NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
17%
57%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (17.4%)
Network19 (82.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (87.0%)
Unknown0 (0.0%)
Required3 (13.0%)
Privileges Required
Low13 (56.5%)
High0 (0.0%)
None10 (43.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Agpt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Agpt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Agpt's Products

View all 2 CNAs →

Top CWEs