Impact
The vulnerability in AutoGPT’s ExtractTextInformationBlock allows malicious content to be provided such that the server consumes disproportionate memory, eventually exhausting resources and causing a denial of service. The primary impact is that an attacker can disrupt the availability of the platform, affecting all users relying on the automated agent service. This weakness corresponds to CWE-770, which denotes an uncontrolled resource consumption flaw.
Affected Systems
The affected product is Significant‑Gravitas AutoGPT, versions prior to 0.6.32. An attacker could target any deployment of AutoGPT that exposes the ExtractTextInformationBlock functionality—such as the community or enterprise releases that do not yet incorporate the 0.6.32 update.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the lack of an EPSS score suggests that publicly known exploitation data is limited or not available. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an external user submitting a large payload to the ExtractTextInformationBlock endpoint; based on the description, the attacker can perpetrate the DoS remotely via the platform’s network interface, provided the endpoint is reachable. No additional prerequisites beyond sending the input are mentioned, so the exploitation condition appears straightforward for an attacker with network access to the AutoGPT instance.
OpenCVE Enrichment