Server-Side Template Injection Vulnerability in AutoGPT by Significant Gravitas
CVE-2025-1040
What is CVE-2025-1040?
AutoGPT versions 0.3.4 and earlier suffer from a Server-Side Template Injection vulnerability due to the improper handling of user-supplied format strings in the AgentOutputBlock component. This weakness allows an attacker to pass malicious input to the Jinja2 templating engine, potentially leading to Remote Code Execution (RCE) on the affected system. Patching to version 0.4.0 is essential to mitigate this risk. Users should immediately update their installations to safeguard against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
significant-gravitas/autogpt < unspecified
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
