AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw in its shell command validation function. Specifically, the vulnerability exists in versions v0.5.0 up to but not including 5.1.0. The issue arises from the application's method of validating shell commands against an allowlist or denylist, where it only checks the first word of the command. This allows an attacker to bypass the intended restrictions by crafting commands that are executed despite not being on the allowlist or by including malicious commands not present in the denylist. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary shell commands.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-17606 | AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw in its shell command validation function. Specifically, the vulnerability exists in versions v0.5.0 up to but not including 5.1.0. The issue arises from the application's method of validating shell commands against an allowlist or denylist, where it only checks the first word of the command. This allows an attacker to bypass the intended restrictions by crafting commands that are executed despite not being on the allowlist or by including malicious commands not present in the denylist. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary shell commands. | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Tue, 05 Aug 2025 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Agpt autogpt Classic
         | 
|
| CPEs | cpe:2.3:a:agpt:autogpt_classic:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Agpt autogpt
         | 
    
        
        Agpt autogpt Classic
         | 
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Tue, 08 Oct 2024 22:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Agpt
         Agpt autogpt  | 
|
| CPEs | cpe:2.3:a:agpt:autogpt:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Agpt
         Agpt autogpt  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T18:56:22.433Z
Reserved: 2024-02-26T02:50:23.895Z
Link: CVE-2024-1881
Updated: 2024-07-19T13:50:24.068Z
Status : Modified
Published: 2024-06-06T19:15:51.920
Modified: 2025-08-05T15:35:27.480
Link: CVE-2024-1881
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD