CRITICAL9.8
PYSEC-2026-257
AutoGPT bypass of the shell commands denylist settings
Details
A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as `whoami` and `/bin/whoami`. An attacker can circumvent this restriction by executing commands with a modified path, such as `/bin/./whoami`, which is not recognized by the denylist.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/agpt
Introduced in:
0No fixed version published yet for agpt (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-6091[ADVISORY]
- https://github.com/significant-gravitas/autogpt/commit/ef691359b774a1f9f80cf4f5ace9821967b718ed[WEB]
- https://github.com/Significant-Gravitas/AutoGPT[PACKAGE]
- https://huntr.com/bounties/8a742c13-bb5e-4bc9-8b86-049d8a386050[WEB]
- https://pypi.org/project/agpt[PACKAGE]
- https://github.com/advisories/GHSA-g84q-54hf-36rg[ADVISORY]