Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r277-3xc5-c79v | AutoGPT is Vulnerable to RCE via Disabled Block Execution |
Tue, 17 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agpt
Agpt autogpt Platform |
|
| CPEs | cpe:2.3:a:agpt:autogpt_platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Agpt
Agpt autogpt Platform |
|
| Metrics |
cvssV3_1
|
Fri, 30 Jan 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Significant-gravitas
Significant-gravitas autogpt |
|
| Vendors & Products |
Significant-gravitas
Significant-gravitas autogpt |
Thu, 29 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both main web API and external API) allow executing blocks by UUID without checking the `disabled` flag. Any authenticated user can execute the disabled `BlockInstallationBlock`, which writes arbitrary Python code to the server filesystem and executes it via `__import__()`, achieving Remote Code Execution. In default self-hosted deployments where Supabase signup is enabled, an attacker can self-register; if signup is disabled (e.g., hosted), the attacker needs an existing account. autogpt-platform-beta-v0.6.44 contains a fix. | |
| Title | AutoGPT is Vulnerable to RCE via Disabled Block Execution | |
| Weaknesses | CWE-276 CWE-863 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-29T21:16:08.779Z
Reserved: 2026-01-26T21:06:47.869Z
Link: CVE-2026-24780
Updated: 2026-01-29T21:16:04.283Z
Status : Analyzed
Published: 2026-01-29T18:16:17.080
Modified: 2026-02-17T16:04:36.780
Link: CVE-2026-24780
No data.
OpenCVE Enrichment
Updated: 2026-04-18T01:30:16Z
Github GHSA