CVE-2025-41023 PUBLISHED

Authentication bypass in AutoGPT de Thesamur

Assigner: INCIBE
Reserved: 16.04.2025 Published: 19.02.2026 Updated: 19.02.2026

An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of the authorisation method used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Thesamur
Product AutoGPT
Versions Default: unaffected
  • Version All versions is affected

Solutions

No solution has been reported at this time.

Credits

  • Gonzalo Aguilar García (6h4ack) finder

References

Problem Types

  • CWE-287 Improper Authentication CWE