AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes blocks without consuming any credits, regardless of the user's balance. The credit check that exists in the graph execution path (manager.py) is never reached when blocks are called directly via the external API, allowing unlimited free execution of all blocks. This vulnerability is fixed in 0.6.59.
Metrics
Affected Vendors & Products
References
History
Fri, 29 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Significant-gravitas
Significant-gravitas autogpt |
|
| Vendors & Products |
Significant-gravitas
Significant-gravitas autogpt |
Thu, 28 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes blocks without consuming any credits, regardless of the user's balance. The credit check that exists in the graph execution path (manager.py) is never reached when blocks are called directly via the external API, allowing unlimited free execution of all blocks. This vulnerability is fixed in 0.6.59. | |
| Title | AutoGP: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/execute | |
| Weaknesses | CWE-770 CWE-841 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T13:36:58.698Z
Reserved: 2026-05-08T16:58:28.896Z
Link: CVE-2026-45023
Updated: 2026-05-29T13:36:42.919Z
Status : Deferred
Published: 2026-05-28T22:17:00.080
Modified: 2026-05-29T16:07:40.747
Link: CVE-2026-45023
No data.
OpenCVE Enrichment
Updated: 2026-05-29T01:15:06Z