CVE-2025-32424: AutoGPT has a DoS vulnerability in ScreenshotWebPageBlock
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, ScreenshotWebPageBlock will store the captured screenshots in a temporary directory. StepThroughItemsBlock can be used to iterate ScreenshotWebPageBlock multiple times. StepThroughItemsBlock does not limit the number of loops. In addition, ScreenshotWebPageBlock does not limit the amount of disk space consumed in the current working directory. When a malicious user chooses to screen shot many web pages, the disk space will eventually run out, causing a DoS. Version 0.6.63 patches the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AutoGPTto a version that resolves this vulnerability.Fixed in 0.6.63
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32424?
The severity of CVE-2025-32424 is high, rated at 8.7.
How do I fix CVE-2025-32424?
To fix CVE-2025-32424, update AutoGPT to version 0.6.63 or later.
What is the impact of CVE-2025-32424?
CVE-2025-32424 allows for a Denial of Service (DoS) vulnerability in the ScreenshotWebPageBlock module.
What software is affected by CVE-2025-32424?
CVE-2025-32424 affects the AutoGPT software prior to version 0.6.63.
When was CVE-2025-32424 published?
CVE-2025-32424 was published on June 18, 2026.