CVE-2026-55237
Significant-Gravitas AutoGPT
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), which is passed to `router.push`. An attacker can craft a malicious link that, when opened by an authenticated user, performs a client-side redirect and executes arbitrary JavaScript in the context of their browser. This could lead to credential theft, internal network pivoting, and unauthorized actions...
- CVSS
- 8.8
- EPSS
- 0.32% 24.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.19