CVE-2025-31491
CVSS 3.1 Score 8.6 of 10 (high)
Details
Summary
CVE-2025-31491 is a vulnerability affecting the AutoGPT platform, where prior to version 0.6.1, the wrong handling of redirects in requests led to the leakage of cross-domain cookies and protected headers. The issue lies in the wrapper around the requests python library, which does not follow security-sensitive headers or cookies when manually re-requesting a new location after a redirect. This can expose Authorization and Proxy-Authorization headers, as demonstrated in the GitHub API example, leading to the leakage of GitHub credentials and private cookies. The vulnerability is fixed in version 0.6.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.