Description
Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt repository, specifically in the GitHub Integration and Web Search blocks. These vulnerabilities affect version agpt-platform-beta-v0.1.1. The issues arise when block inputs are controlled by untrusted sources, leading to potential credential leakage, internal network scanning, and unauthorized access to internal services, APIs, or data stores. The affected blocks include GithubListPullRequestsBlock, GithubReadPullRequestBlock, GithubAssignPRReviewerBlock, GithubListPRReviewersBlock, GithubUnassignPRReviewerBlock, GithubCommentBlock, GithubMakeIssueBlock, GithubReadIssueBlock, GithubListIssuesBlock, GithubAddLabelBlock, GithubRemoveLabelBlock, GithubListBranchesBlock, and ExtractWebsiteContentBlock.
INFO
Published Date :
2025-03-20T10:11:37.407Z
Last Modified :
2025-03-20T18:26:13.090Z
Source :
@huntr_ai
AFFECTED PRODUCTS
The following products are affected by CVE-2024-10457 vulnerability.
| Vendors | Products |
|---|---|
| Significant-gravitas |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-10457.