google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
880 stars 179 forks source link

AI PRP: AutoGPT Exposed API Remote Code Execution #506

Open secureness opened 5 months ago

secureness commented 5 months ago

several configurations and setup methods can lead to remote code execution by simply sending an HTTP request.

Ref: https://huntr.com/bounties/1be74477-b338-45f5-a752-b91224994598 setup with docker-compose: https://docs.agpt.co/autogpt/setup/docker/#basic-setup