Vulnerabilities in significant-gravitas
41 resultsVexday analysis
A Significant Gravitas apresenta um perfil de risco moderado com 8 vulnerabilidades catalogadas, sendo 1 de severidade crítica. Não há evidência de exploração ativa em campo (0 no KEV), e nenhuma vulnerabilidade foi publicada nos últimos 90 dias, sugerindo um risco atual contido. A fraqueza dominante é injeção de comando (CWE-78), típica de falhas em validação de entrada, exigindo atenção em processos de sanitização de dados.
CVE-2025-32424HIGHAutoGPT has a DoS vulnerability in ScreenshotWebPageBlockEPSS 0.4%CVE-2026-33232HIGHAutoGPT: Unauthenticated DoS via Disk Space ExhaustionEPSS 0.4%CVE-2025-32393HIGHAutoGPT has a DoS vulnerability in ReadRSSFeedBlockEPSS 0.4%CVE-2026-30950HIGHAutoGPT has Authenticated Session Hijacking via IDOREPSS 0.4%CVE-2025-32436HIGHAutoGPT has a DoS vulnerability in AddAudioToVideoBlockEPSS 0.4%CVE-2025-31494LOWAutoGPT allows cross-user sharing of node execution results through WebSockets APIEPSS 0.4%CVE-2023-37273HIGHDocker escape in Auto-GPT when running from docker-compose.yml included in git repoEPSS 0.4%CVE-2025-62615CRITICALAutoGPT has SSRF vulnerability in ReadRSSFeedBlockEPSS 0.4%CVE-2023-37274HIGHPython code execution sandbox escape in non-docker version in Auto-GPTEPSS 0.4%CVE-2025-62616CRITICALAutoGPT has SSRF vulnerability in SendDiscordFileBlockEPSS 0.3%CVE-2026-55237HIGHAutoGPT SignUp Page has DOM-Based XSS and Open RedirectEPSS 0.3%CVE-2026-33235HIGHAutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating featuresEPSS 0.3%CVE-2026-33234MEDIUMAutoGPT: SendEmailBlock's IP blocklist bypass allows SSRF via user-controlled SMTP serverEPSS 0.3%CVE-2025-32394MEDIUMAutoGPT: There is a DoS vulnerability in AITextSummarizerBlockEPSS 0.2%CVE-2025-32423MEDIUMAutoGPT: There is a DoS vulnerability in ExtractTextInformationBlockEPSS 0.2%CVE-2026-33233HIGHAutoGPT Platform: Remote Code Execution via Unsafe Pickle Deserialization of Redis Cache EntriesEPSS 0.2%CVE-2026-56663HIGHAutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass and internal `pg-meta` accessEPSS 0.2%CVE-2026-45023MEDIUMAutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/executeEPSS 0.2%CVE-2025-32425MEDIUMAutoGPT has missing Docker log rotation on platform containers that allows host disk-exhaustion DoSEPSS 0.2%CVE-2026-56823MEDIUMAutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping TriggeringEPSS 0.1%