CVE-2024-8156

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 94

Summary

CVE-2024-8156 is a command injection vulnerability affecting the workflow-checker.yml workflow of significant-gravitas/autogpt. The vulnerability stems from the insecure use of the `github.head.ref` user input, which can be exploited by attackers to inject arbitrary commands. This issue can be exploited by creating a maliciously named branch and opening a pull request. The vulnerability impacts all versions up to and including the latest, potentially granting attackers reverse shell access or theft of sensitive tokens and keys.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share