CVE-2024-8156: Agpt Autogpt Classic

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.ref` is used insecurely, allowing an attacker to inject arbitrary commands. This vulnerability affects versions up to and including the latest version. An attacker can exploit this by creating a branch name with a malicious payload and opening a pull request, potentially leading to reverse shell access or theft of sensitive tokens and keys.

Affected products

  • Agpt Autogpt Classic: before 0.5.1 (fixed in 0.5.1)

Published 2025-03-20. Last modified 2026-06-17.