CVE-2025-31494

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Apr 15, 2025
CWE ID 200
CWE ID 284

Summary

CVE-2025-31494 is a vulnerability affecting the AutoGPT Platform's WebSocket API. This issue stems from the lack of a check to prevent users from subscribing with another user's graph_id+graph_version. As a result, node execution updates from one user's graph execution can be received by another user within the same instance, leading to unintended access to data or functionality. This vulnerability does not affect instances running in different environments or those with no user access. Its impact is limited in private instances with user white-lists. The vulnerability has been addressed in version 0.6.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share