Vulnerability Details CVE-2025-22603
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Versions prior to autogpt-platform-beta-v0.4.2 contains a server-side request forgery (SSRF) vulnerability inside component (or block) `Send Web Request`. The root cause is that IPV6 address is not restricted or filtered, which allows attackers to perform a server side request forgery to visit an IPV6 service. autogpt-platform-beta-v0.4.2 fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.2%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2025-22603
-
cpe:2.3:a:agpt:autogpt_platform:0.1.0
-
cpe:2.3:a:agpt:autogpt_platform:0.1.1
-
cpe:2.3:a:agpt:autogpt_platform:0.2.0
-
cpe:2.3:a:agpt:autogpt_platform:0.2.1
-
cpe:2.3:a:agpt:autogpt_platform:0.2.2
-
cpe:2.3:a:agpt:autogpt_platform:0.3.0
-
cpe:2.3:a:agpt:autogpt_platform:0.3.1
-
cpe:2.3:a:agpt:autogpt_platform:0.3.2
-
cpe:2.3:a:agpt:autogpt_platform:0.3.3
-
cpe:2.3:a:agpt:autogpt_platform:0.3.4
-
cpe:2.3:a:agpt:autogpt_platform:0.4.0
-
cpe:2.3:a:agpt:autogpt_platform:0.4.1