google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

AI PRP: AutoGPT Exposed API Remote Code Execution #506

Open secureness opened 2 weeks ago

secureness commented 2 weeks ago

several configurations and setup methods can lead to remote code execution by simply sending an HTTP request.

Ref: https://huntr.com/bounties/1be74477-b338-45f5-a752-b91224994598 setup with docker-compose: https://docs.agpt.co/autogpt/setup/docker/#basic-setup