Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-0454

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 7.5
CVSS3: 7.5
EPSS Низкий

Описание

A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. The vulnerability arises due to a hostname confusion between the urlparse function from the urllib.parse library and the requests library. A malicious user can exploit this by submitting a specially crafted URL, such as http://localhost:\@google.com/../, to bypass the SSRF check and perform an SSRF attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:agpt:autogpt_platform:*:*:*:*:*:*:*:*
Версия до 0.4.0 (исключая)

EPSS

Процентиль: 27%
0.00096
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
github
11 месяцев назад

A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. The vulnerability arises due to a hostname confusion between the `urlparse` function from the `urllib.parse` library and the `requests` library. A malicious user can exploit this by submitting a specially crafted URL, such as `http://localhost:\@google.com/../`, to bypass the SSRF check and perform an SSRF attack.

EPSS

Процентиль: 27%
0.00096
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-918