Cross-Domain Cookie Leakage in AutoGPT by Significant Gravitas
CVE-2025-31491
8.6HIGH
What is CVE-2025-31491?
AutoGPT, a platform for managing AI agents, has a vulnerability that allows for cross-domain leakage of sensitive headers and cookies due to improper handling of redirects. When using the requests Python library, the system fails to adequately filter security-sensitive headers during re-requests to external URLs. If exploited via an open redirect on third-party sites, users' Authorization and Proxy-Authorization headers, along with cookies, could be inadvertently exposed, risking user credentials and privacy. This flaw was addressed in version 0.6.1, highlighting the importance of secure data handling in AI workflows.
Affected Version(s)
AutoGPT < 0.6.1