CVE-2025-41023Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of the authorisation method used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-19: 2Technical Details · 2026-02-19: 102-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️#INCIBEaviso | Omisión de autenticación en AutoGPT de #Thesamur #CVE #CVE-2025-41023 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/omision-de-autenticacion-en-autogpt-de-thesamur #AvisosDeSeguridad #TI #CNA #0day https://t.co/Fjp2NBWalf

    Post summary

    The tweet announces a newly identified authentication‑omission vulnerability (CVE‑2025‑41023) in AutoGPT by Thesamur, providing a link to an Incibe alert but no details on PoC, exploitation, or fixes.

    01010419
    42.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-41023 An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside th… https://www.cve.org/CVERecord?id=CVE-2025-41023

    Post summary

    CVE-2025-41023 is an authentication‑bypass flaw in Thesamur's AutoGPT that lets attackers circumvent authentication mechanisms; no PoC, exploit, or patch information is provided.

    0000059
    56.4K followersView on X

Explore more