CVE-2025-53944

Source
https://cve.org/CVERecord?id=CVE-2025-53944
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53944.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-53944
Aliases
  • GHSA-x77j-qg2x-fgg6
Published
2025-07-30T14:28:36.168Z
Modified
2026-04-10T05:31:01.828954Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
AutoGPT Platform Exposes Graph Execution Results via Authorization Gap
Details

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external API's getgraphexecutionresults endpoint has an authorization bypass vulnerability. While it correctly validates user access to the graphid, it fails to verify ownership of the graphexecid parameter, allowing authenticated users to access any execution results by providing arbitrary execution IDs. The internal API implements proper validation for both parameters. This is fixed in v0.6.16.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53944.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-285"
    ]
}
References

Affected packages

Git / github.com/significant-gravitas/autogpt

Affected ranges

Type
GIT
Repo
https://github.com/significant-gravitas/autogpt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/significant-gravitas/autogpt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

agbenchmark-v0.*
agbenchmark-v0.0.10
agpt-platform-beta-v0.*
agpt-platform-beta-v0.1.0
agpt-platform-beta-v0.1.1
agpt-platform-beta-v0.2.0
autogpt-platform-beta-v0.*
autogpt-platform-beta-v0.2.2
autogpt-platform-beta-v0.3.2
autogpt-platform-beta-v0.3.3
autogpt-platform-beta-v0.3.4
autogpt-platform-beta-v0.4.0
autogpt-platform-beta-v0.4.1
autogpt-platform-beta-v0.4.10
autogpt-platform-beta-v0.4.11
autogpt-platform-beta-v0.4.2
autogpt-platform-beta-v0.4.3
autogpt-platform-beta-v0.4.4
autogpt-platform-beta-v0.4.5
autogpt-platform-beta-v0.4.8
autogpt-platform-beta-v0.4.9
autogpt-platform-beta-v0.5.0
autogpt-platform-beta-v0.5.1
autogpt-platform-beta-v0.6.0
autogpt-platform-beta-v0.6.1
autogpt-platform-beta-v0.6.10
autogpt-platform-beta-v0.6.11
autogpt-platform-beta-v0.6.12
autogpt-platform-beta-v0.6.13
autogpt-platform-beta-v0.6.14
autogpt-platform-beta-v0.6.15
autogpt-platform-beta-v0.6.2
autogpt-platform-beta-v0.6.4
autogpt-platform-beta-v0.6.5
autogpt-platform-beta-v0.6.6
autogpt-platform-beta-v0.6.7
autogpt-platform-beta-v0.6.8
autogpt-platform-beta-v0.6.9
v0.*
v0.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53944.json"