CVE-2026-24780Disclosure(agpt / autogpt_platform)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch agpt autogpt_platform systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both main web API and external API) allow executing blocks by UUID without checking the `disabled` flag. Any authenticated user can execute the disabled `BlockInstallationBlock`, which writes arbitrary Python code to the server filesystem and executes it via `__import__()`, achieving Remote Code Execution. In default self-hosted deployments where Supabase signup is enabled, an attacker can self-register; if signup is disabled (e.g., hosted), the attacker needs an existing account. autogpt-platform-beta-v0.6.44 contains a fix.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-276CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • autogpt_platform

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 2 mentions (2026-01-29); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
autogpt_platform

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-01-29: 2Mentions · 2026-02-04: 1Mentions · 2026-02-22: 1Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-27: 101-2902-0402-2202-2302-2402-2502-27
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-01-292
Disclosure1General1
2026-02-041
Disclosure1
2026-02-221
Disclosure1
2026-02-231
Disclosure1
2026-02-241
Disclosure1
2026-02-251
Patch1
2026-02-271
Disclosure1
Full discourse8 posts
  • rahul@rahulgovind517
    Disclosure

    Advisory: https://github.com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-r277-3xc5-c79v CVE: https://nvd.nist.gov/vuln/detail/CVE-2026-24780

    Post summary

    The text shares links to a GitHub advisory and the NVD entry for CVE-2026-24780, indicating a disclosure but providing no further detail.

    00020165
    62 followersView on X
  • Prateek Tomar@TomarPrateek23
    Disclosure

    New vulnerability disclosed: CVE-2026-24780 with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    A new vulnerability, CVE-2026-24780, has been disclosed with a high CVSS score; however, no proof of concept, exploit code, active exploitation, or patch information is provided.

    0000045
    88 followersView on X
  • Prateek Tomar@TomarPrateek23
    Patch

    CVE-2026-24780 has been published with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Add it to your patching queue if applicable. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    CVE-2026-24780 is a high‑severity vulnerability (CVSS 8.8) that should be added to patching queues; no PoC or exploitation details are provided.

    0000042
    87 followersView on X
  • Prateek Tomar@TomarPrateek23
    Disclosure

    New vulnerability disclosed: CVE-2026-24780 with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    A new vulnerability, CVE-2026-24780, has been disclosed with a CVSS score of 8.8, potentially impacting the AutoGPT platform; further details are available at the provided link.

    0000056
    86 followersView on X
  • Prateek Tomar@TomarPrateek23
    Disclosure

    Security advisory: CVE-2026-24780 with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The advisory announces CVE-2026-24780 with a CVSS score of 8.8 and urges users to check if action is needed, but provides no PoC, exploit, or patch details.

    0000040
    80 followersView on X
  • Prateek Tomar@TomarPrateek23
    Disclosure

    New vulnerability disclosed: CVE-2026-24780 with a CVSS score of 8.8. AutoGPT is a platform that allows users to create,.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    A new vulnerability, CVE-2026-24780, has been disclosed with a high CVSS score of 8.8, and a link to further details is provided.

    0000050
    80 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24780 Remote Code Execution in AutoGPT Platform via Disabled Block Execution Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24780

    Post summary

    CVE-2026-24780 is a remote code execution vulnerability in the AutoGPT Platform caused by a disabled block execution endpoint; the announcement provides technical details but no proof of exploitation, fix, or PoC.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24780 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-plat… https://www.cve.org/CVERecord?id=CVE-2026-24780

    Post summary

    The entry simply cites CVE‑2026‑24780 and briefly describes the AutoGPT platform, offering no evidence of exploits, patches, or technical details.

    00000152
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appagptautogpt_platform---

Explore more