Open am0o0 opened 2 months ago
According to recent CVE-2024-6091 we can execute arbitrary commands on the popular AutoGPT AI-based application.
once we run the AutoGPT it'll open an http server which if the server is exposed to the public network then attackers can run arbitrary OS commands.
update: the original PoC: https://huntr.com/bounties/8a742c13-bb5e-4bc9-8b86-049d8a386050
@tooryx as you told me I want to work on this AI PRP parallelly.
Hi @am0o0,
You can start working on this.
~tooryx
According to recent CVE-2024-6091 we can execute arbitrary commands on the popular AutoGPT AI-based application.
once we run the AutoGPT it'll open an http server which if the server is exposed to the public network then attackers can run arbitrary OS commands.
update: the original PoC: https://huntr.com/bounties/8a742c13-bb5e-4bc9-8b86-049d8a386050