CVE-2025-41023

MEDIUM

AutoGPT - Auth Bypass

Title source: llm
STIX 2.1

Description

An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of the authorisation method used.

Scores

CVSS v4 6.9
EPSS 0.0003
EPSS Percentile 9.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
Thesamur/AutoGPT All versions
Published Feb 19, 2026
Tracked Since Feb 19, 2026