CVE-2025-31491

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1, AutoGPT allows of leakage of cross-domain cookies and protected headers in requests redirect. AutoGPT uses a wrapper around the requests python library, located in autogpt_platform/backend/backend/util/request.py. In this wrapper, redirects are specifically NOT followed for the first request. If the wrapper is used with allow_redirects set to True (which is the default), any redirect is not followed by the initial request, but rather re-requested by the wrapper using the new location. However, there is a fundamental flaw in manually re-requesting the new location: it does not account for security-sensitive headers which should not be sent cross-origin, such as the Authorization and Proxy-Authorization header, and cookies. For example in autogpt_platform/backend/backend/blocks/github/_api.py, an Authorization header is set when retrieving data from the GitHub API. However, if GitHub suffers from an open redirect vulnerability (such as the made-up example of https://api.github.com/repos/{owner}/{repo}/issues/comments/{comment_id}/../../../../../redirect/?url=https://joshua.hu/), and the script can be coerced into visiting it with the Authorization header, the GitHub credentials in the Authorization header will be leaked. This allows leaking auth headers and private cookies. This vulnerability is fixed in 0.6.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:agpt:autogpt_platform:*:*:*:*:*:*:*:*

History

05 Aug 2025, 17:04

Type Values Removed Values Added
First Time Agpt autogpt Platform
CPE cpe:2.3:a:agpt:autogpt:*:*:*:*:*:*:*:* cpe:2.3:a:agpt:autogpt_platform:*:*:*:*:*:*:*:*

21 May 2025, 20:25

Type Values Removed Values Added
CPE cpe:2.3:a:agpt:autogpt:*:*:*:*:*:*:*:*
First Time Agpt
Agpt autogpt
CWE CWE-601
References () https://github.com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-ggcm-93qg-gfhp - () https://github.com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-ggcm-93qg-gfhp - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.6

15 Apr 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 00:15

Updated : 2025-08-05 17:04


NVD link : CVE-2025-31491

Mitre link : CVE-2025-31491


JSON object : View

Products Affected

agpt

  • autogpt_platform
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')