VYPR
Critical severity9.8NVD Advisory· Published Sep 11, 2024· Updated Jun 17, 2026

CVE-2024-6091

CVE-2024-6091

Description

A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as 'whoami' and '/bin/whoami'. An attacker can circumvent this restriction by executing commands with a modified path, such as '/bin/./whoami', which is not recognized by the denylist.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
agptPyPI
<= 0.5.1

Affected products

3
  • cpe:2.3:a:agpt:autogpt_classic:0.5.1:*:*:*:*:*:*:*
  • ghsa-coords
    Range: <= 0.5.1
  • significant-gravitas/significant-gravitas/autogptv5
    Range: unspecified

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.