Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AI PRP: Commnad injection in significant-gravitas/autogpt #536

Open
am0o0 opened this issue Sep 12, 2024 · 2 comments
Open

AI PRP: Commnad injection in significant-gravitas/autogpt #536

am0o0 opened this issue Sep 12, 2024 · 2 comments
Assignees
Labels
ai-bounty-prp Identify an AI bounty plugin Contributor main The main issue a contributor is working on (top of the contribution queue).

Comments

@am0o0
Copy link
Contributor

am0o0 commented Sep 12, 2024

According to recent CVE-2024-6091 we can execute arbitrary commands on the popular AutoGPT AI-based application.

once we run the AutoGPT it'll open an http server which if the server is exposed to the public network then attackers can run arbitrary OS commands.

update: the original PoC: https://huntr.com/bounties/8a742c13-bb5e-4bc9-8b86-049d8a386050

@am0o0
Copy link
Contributor Author

am0o0 commented Sep 12, 2024

@tooryx as you told me I want to work on this AI PRP parallelly.

@tooryx tooryx added Contributor main The main issue a contributor is working on (top of the contribution queue). ai-bounty-prp Identify an AI bounty plugin labels Sep 17, 2024
@tooryx
Copy link
Member

tooryx commented Sep 17, 2024

Hi @am0o0,

You can start working on this.

~tooryx

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ai-bounty-prp Identify an AI bounty plugin Contributor main The main issue a contributor is working on (top of the contribution queue).
Projects
None yet
Development

No branches or pull requests

2 participants