VDB
Sign up
CRITICAL9.8

PYSEC-2026-257

AutoGPT bypass of the shell commands denylist settings

Details

A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as `whoami` and `/bin/whoami`. An attacker can circumvent this restriction by executing commands with a modified path, such as `/bin/./whoami`, which is not recognized by the denylist.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/agpt
Introduced in: 0

No fixed version published yet for agpt (pip). Pin to a known-safe version or switch to an alternative.

References