Denial of Service Vulnerability in AutoGPT by Significant Gravitas
CVE-2025-32424
8.7HIGH
What is CVE-2025-32424?
AutoGPT, a workflow automation platform designed for creating and managing continuous AI agents, has a vulnerability that allows a malicious user to exploit the ScreenshotWebPageBlock. Prior to version 0.6.63, this block captures screenshots and stores them in a temporary directory without limiting the number of iterations by the StepThroughItemsBlock. The unregulated screenshot storage can lead to excessive disk space consumption, resulting in a Denial of Service (DoS) condition as the current working directory fills up. Version 0.6.63 addresses this vulnerability by imposing necessary restrictions.
Affected Version(s)
AutoGPT < 0.6.63
