Impact
The vulnerability is in the AITextSummarizerBlock of AutoGPT, allowing malicious users to submit large content payloads that cause the server to allocate an extreme amount of memory, eventually exhausting resources and causing a denial of service. This weakness is related to improper input validation and unchecked memory allocation (CWE-405 and CWE-770).
Affected Systems
Significant-Gravitas AutoGPT versions prior to 0.6.32 are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available and the vulnerability does not appear in the CISA KEV catalog. Attackers can trigger the DoS by sending oversized content to the AITextSummarizerBlock endpoint from any remote user role; no special privileges are required.
OpenCVE Enrichment