CVE-2025-62616: AutoGPT has SSRF vulnerability in SendDiscordFileBlock
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.34, in SendDiscordFileBlock, the third-party library aiohttp.ClientSession().get is used directly to access the URL, but the input URL is not filtered, which will cause SSRF vulnerability. This issue has been patched in autogpt-platform-beta-v0.6.34.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62616?
The severity of CVE-2025-62616 is currently classified as high due to its potential for remote server-side request forgery.
How do I fix CVE-2025-62616?
To fix CVE-2025-62616, upgrade to the version autogpt-platform-beta-v0.6.34 or later which addresses the vulnerability.
What software is affected by CVE-2025-62616?
CVE-2025-62616 affects versions of AutoGPT prior to autogpt-platform-beta-v0.6.34.
What components of AutoGPT are involved in CVE-2025-62616?
CVE-2025-62616 involves the SendDiscordFileBlock functionality within AutoGPT.
Can CVE-2025-62616 be exploited remotely?
Yes, CVE-2025-62616 can be exploited remotely, making it a significant security risk.