High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2025-0454
CVE-2025-0454
Description
A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. The vulnerability arises due to a hostname confusion between the urlparse function from the urllib.parse library and the requests library. A malicious user can exploit this by submitting a specially crafted URL, such as http://localhost:\@google.com/../, to bypass the SSRF check and perform an SSRF attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <v0.4.0
- significant-gravitas/significant-gravitas/autogptv5Range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/significant-gravitas/autogpt/commit/ff065cd24c2289878c0abdb9adbf91c305f0d70anvdPatch
- huntr.com/bounties/0664fdee-bdc2-4650-8075-74d7b8d3e308nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.