CVE-2024-6091

CVSS V2 None CVSS V3 None
Description
A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as 'whoami' and '/bin/whoami'. An attacker can circumvent this restriction by executing commands with a modified path, such as '/bin/./whoami', which is not recognized by the denylist.
Overview
  • CVE ID
  • CVE-2024-6091
  • Assigner
  • @huntr_ai
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-09-11T12:49:07.293Z
  • Last Modified Date
  • 2024-09-11T18:23:23.728Z
History
Created Old Value New Value Data Type Notes
2024-09-12 13:08:48 Added to TrackCVE