AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the improper handling of user-supplied format strings in the `AgentOutputBlock` implementation, where malicious input is passed to the Jinja2 templating engine without adequate security measures. Attackers can exploit this flaw to execute arbitrary commands on the host system. The issue is fixed in version 0.4.0.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Agpt
Agpt autogpt |
|
CPEs | cpe:2.3:a:agpt:autogpt:*:*:*:*:*:*:*:* | |
Vendors & Products |
Agpt
Agpt autogpt |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the improper handling of user-supplied format strings in the `AgentOutputBlock` implementation, where malicious input is passed to the Jinja2 templating engine without adequate security measures. Attackers can exploit this flaw to execute arbitrary commands on the host system. The issue is fixed in version 0.4.0. | |
Title | Server-Side Template Injection (SSTI) in significant-gravitas/autogpt | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T15:22:10.534Z
Reserved: 2025-02-04T19:56:24.203Z
Link: CVE-2025-1040

Updated: 2025-03-20T15:22:06.904Z

Status : Analyzed
Published: 2025-03-20T10:15:53.653
Modified: 2025-04-01T20:19:55.317
Link: CVE-2025-1040

No data.