CVE-2025-31494
CVSS 3.1 Score 3.5 of 10 (low)
Details
Summary
CVE-2025-31494 is a vulnerability affecting the AutoGPT Platform's WebSocket API. This issue stems from the lack of a check to prevent users from subscribing with another user's graph_id+graph_version. As a result, node execution updates from one user's graph execution can be received by another user within the same instance, leading to unintended access to data or functionality. This vulnerability does not affect instances running in different environments or those with no user access. Its impact is limited in private instances with user white-lists. The vulnerability has been addressed in version 0.6.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.