Denial of Service Risk in AutoGPT Platform from Significant Gravitas
CVE-2025-31490
What is CVE-2025-31490?
The AutoGPT platform, designed for managing AI agents, previously contained a vulnerability that exposed it to server-side request forgery (SSRF) due to inadequate DNS resolution validation. Specifically, before version 0.6.1, the platform's request processing allowed malicious actors to exploit DNS rebinding attacks. The flawed validation check only ensured the requested hostname did not resolve to local IP addresses at initial validation, potentially leading to further exploitation once the URL was passed to the actual request function. This flaw has been addressed in version 0.6.1, improving security measures against such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AutoGPT < 0.6.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
