Agpt maintains a modestly represented but prominent vulnerability footprint across its AutoGPT platform and related automation products, which sit at the intersection of code generation, command execution, and external service integration. The vendor's vulnerabilities skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the inherent risks of dynamically generated and executed code. The exposure recurs through weakness classes including server-side request forgery, code injection, OS command injection, resource exhaustion, and sensitive information disclosure—structural hazards that arise from the automation and agent-execution model underlying these tools. Defenders should prioritize patching releases from this vendor, particularly in environments where AutoGPT instances have network or system access. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Agpt over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62615CRITICAL AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6 | Feb 4, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-26020HIGH AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.48, an authenticated u | Feb 12, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-24780HIGH AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6 | Jan 29, 2026 | 8.8 | 31 | NO | NO |
CVE-2024-6091CRITICAL A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to | Sep 11, 2024 | 9.8 | 31 | NO | NO |
CVE-2025-62616CRITICAL AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6 | Feb 4, 2026 | 9.8 | 30 | NO | NO |
CVE-2025-1040HIGH AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the impro | Mar 20, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-8156CRITICAL A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.ref` is used insecurely, allowi | Mar 20, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-1881CRITICAL AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw i | Jun 6, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-22038HIGH AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6 | Feb 4, 2026 | 8.1 | 26 | NO | NO |
CVE-2025-53944HIGH AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external API's get_graph_execution_result | Jul 30, 2025 | 7.7 | 26 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Agpt.
Media articles that mention a CVE ID that affects a product developed by Agpt — matched by CVE ID, not by vendor name.