
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24780 is a Remote Code Execution (RCE) vulnerability in the AutoGPT Platform caused by disabled block execution bypass. Any authenticated user can invoke the intentionally disabled BlockInstallationBlock — which writes and executes arbitrary Python code on the server — because block execution endpoints fail to check the disabled flag. Affected versions span autogpt_platform >= 0.1.0 and < 0.6.44 (vendor package agpt/autogpt_platform). The advisory was published on January 29, 2026. The CVSS v3.1 base score is 8.8 (High); the CVSS v4.0 base score is 8.6 (High) (GitHub Advisory).
The root cause is an authorization enforcement gap (CWE-863: Incorrect Authorization) combined with code injection (CWE-94) and incorrect default permissions (CWE-276). The block listing endpoint correctly filters disabled blocks (if not b.disabled), but both the main web API (POST /blocks/{block_id}/execute in v1.py#L355-395) and the external API (POST /external-api/v1/blocks/{id}/execute in external/v1/routes.py#L79-93) execute any block by UUID without checking the disabled flag. The dangerous BlockInstallationBlock (UUID 45e78db5-03e9-447f-9395-308d712f5f08, hardcoded in public source) accepts arbitrary Python code, writes it to the server's backend/blocks/ directory, and immediately executes it via __import__(). An attacker can also mint an API key with EXECUTE_BLOCK permission via the main API and invoke the external route, providing a second exploitation path (GitHub Advisory, AutoGPT block.py).
Successful exploitation grants an attacker full Remote Code Execution on the backend server as the service account running the AutoGPT Platform process. This enables complete server compromise, exfiltration of all user data, credentials, and API keys stored in the database, access to environment variables containing cloud credentials and secrets, lateral movement to connected infrastructure (Redis, PostgreSQL, cloud services), and installation of persistent backdoors. The impact extends beyond the directly vulnerable system to any downstream infrastructure reachable from the compromised server (GitHub Advisory).
The vulnerability requires only a low-privilege authenticated account; in default self-hosted deployments where Supabase signup is enabled, an attacker can self-register at no cost. The disabled block's UUID (45e78db5-03e9-447f-9395-308d712f5f08) is hardcoded in the public open-source repository, making target identification trivial. A proof-of-concept is included in the official security advisory. The EPSS score is approximately 0.096% (low automated exploitation probability at time of publication), and there is no current evidence of in-the-wild exploitation or CISA KEV listing (GitHub Advisory, Feedly).
EXECUTE_BLOCK permission via POST /api-keys.Block that executes arbitrary OS commands (e.g., via subprocess.check_output). The class must contain a UUID in its id field and a class name matching class <Name>(Block):.code parameter:curl -X POST "https://<target>/api/blocks/45e78db5-03e9-447f-9395-308d712f5f08/execute" \
-H "Cookie: session=<session_token>" \
-H "Content-Type: application/json" \
-d '{"code": "<malicious_python_code>"}'EXECUTE_BLOCK permission, then call POST /external-api/v1/blocks/45e78db5-03e9-447f-9395-308d712f5f08/execute with the same payload.BlockInstallationBlock.run() method writes the attacker's Python code to backend/blocks/<uuid>.py on the server filesystem and immediately imports and executes it via __import__(), achieving RCE./api/blocks/45e78db5-03e9-447f-9395-308d712f5f08/execute or /external-api/v1/blocks/45e78db5-03e9-447f-9395-308d712f5f08/execute; outbound connections from the backend server to unknown external IPs (reverse shell activity)..py files appearing in the autogpt_platform/backend/backend/blocks/ directory with UUID-formatted filenames (e.g., aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee.py); newly created Python files containing subprocess, os.system, or network socket calls.45e78db5-03e9-447f-9395-308d712f5f08; Python import errors or tracebacks in application logs related to dynamically loaded block modules; unexpected API key creation events (POST /api-keys) followed immediately by external API block execution calls.bash, sh, curl, wget, python3 with suspicious arguments); unexpected network listeners or connections initiated by the backend service account.Upgrade AutoGPT Platform to version autogpt-platform-beta-v0.6.44 or later, which adds an explicit disabled flag check to both execution endpoints (returning HTTP 403 for disabled blocks). Note that at the time of advisory publication, the fix was available in the GitHub release but had not yet been published to the PyPI registry — verify the installed package version carefully. As an interim workaround for hosted deployments, disable user self-registration (Supabase signup) to prevent unauthenticated account creation, and audit all execution logs for requests referencing the block UUID 45e78db5-03e9-447f-9395-308d712f5f08 (GitHub Advisory).
The vulnerability was reported by security researcher rahulgovind and published via GitHub's security advisory program on January 29, 2026. A brief write-up was published by Infinit Security at infinitsec.net covering the RCE via disabled block execution. The CVE received automated tracking coverage from vulnerability aggregators including VulnDB, CIRCL, and Vulners shortly after disclosure. No major vendor statements beyond the official advisory or significant threat actor attribution have been reported (GitHub Advisory, Infinit Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."