Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AI PRP: AutoGPT Exposed API Remote Code Execution #506

Open
secureness opened this issue Jun 15, 2024 · 2 comments
Open

AI PRP: AutoGPT Exposed API Remote Code Execution #506

secureness opened this issue Jun 15, 2024 · 2 comments
Assignees
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this.

Comments

@secureness
Copy link
Contributor

secureness commented Jun 15, 2024

several configurations and setup methods can lead to remote code execution by simply sending an HTTP request.

Ref: https://huntr.com/bounties/1be74477-b338-45f5-a752-b91224994598
setup with docker-compose: https://docs.agpt.co/platform/getting-started/

@tooryx tooryx added the Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. label Jun 24, 2024
@secureness
Copy link
Contributor Author

@tooryx My Main AI PRP is not the priority, I want to ask you to allow me to work on this issue for 3 reasons:

  1. it is a RCE
  2. the autogpt repository is one of the most popular AI open-source repositories with 171K stars! (https://github.com/Significant-Gravitas/AutoGPT)
  3. it have a very simple testbed setup and exploit( only 3 simple curl command can lead to RCE)

I'd like to start working on this ASAP.

@secureness
Copy link
Contributor Author

Also CC for @maoning

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this.
Projects
None yet
Development

No branches or pull requests

2 participants