Cross-Domain Cookie Leakage in AutoGPT by Significant Gravitas
CVE-2025-31491
What is CVE-2025-31491?
AutoGPT, a platform for managing AI agents, has a vulnerability that allows for cross-domain leakage of sensitive headers and cookies due to improper handling of redirects. When using the requests Python library, the system fails to adequately filter security-sensitive headers during re-requests to external URLs. If exploited via an open redirect on third-party sites, users' Authorization and Proxy-Authorization headers, along with cookies, could be inadvertently exposed, risking user credentials and privacy. This flaw was addressed in version 0.6.1, highlighting the importance of secure data handling in AI workflows.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AutoGPT < 0.6.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
