CVE-2026-33232
HIGHAutoGPT: Unauthenticated DoS via Disk Space Exhaustion
Title source: cnaDescription
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial of Service (DoS) through the server due to uncontrolled disk space consumption. The download_agent_file endpoint creates persistent temporary files for every request but fails to delete them after they are served. An unauthenticated attacker can repeatedly call this endpoint to exhaust the server's disk space, causing the database or other system services to fail due to "No space left on device" errors, rendering the entire AutoGPT Platform backend unavailable to all users. This issue has been patched in version 0.6.52.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-374w-2pxq-c9jp
X_Refsource_Misc x_refsource_misc
https://github.com/Significant-Gravitas/AutoGPT/releases/tag/autogpt-platform-beta-v0.6.52
Scores
CVSS v3
7.5
EPSS
0.0007
EPSS Percentile
21.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
CWE-459
CWE-770
Status
published
Products (1)
Significant-Gravitas/AutoGPT
>= 0.4.2, < 0.6.52
Published
May 19, 2026
Tracked Since
May 19, 2026