CVE-2026-24780: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-24780 is a Remote Code Execution (RCE) vulnerability in the AutoGPT Platform caused by disabled block execution bypass. Any authenticated user can invoke the intentionally disabled BlockInstallationBlock — which writes and executes arbitrary Python code on the server — because block execution endpoints fail to check the disabled flag. Affected versions span autogpt_platform >= 0.1.0 and < 0.6.44 (vendor package agpt/autogpt_platform). The advisory was published on January 29, 2026. The CVSS v3.1 base score is 8.8 (High); the CVSS v4.0 base score is 8.6 (High) (GitHub Advisory).

Technical details

The root cause is an authorization enforcement gap (CWE-863: Incorrect Authorization) combined with code injection (CWE-94) and incorrect default permissions (CWE-276). The block listing endpoint correctly filters disabled blocks (if not b.disabled), but both the main web API (POST /blocks/{block_id}/execute in v1.py#L355-395) and the external API (POST /external-api/v1/blocks/{id}/execute in external/v1/routes.py#L79-93) execute any block by UUID without checking the disabled flag. The dangerous BlockInstallationBlock (UUID 45e78db5-03e9-447f-9395-308d712f5f08, hardcoded in public source) accepts arbitrary Python code, writes it to the server's backend/blocks/ directory, and immediately executes it via __import__(). An attacker can also mint an API key with EXECUTE_BLOCK permission via the main API and invoke the external route, providing a second exploitation path (GitHub Advisory, AutoGPT block.py).

Impact

Successful exploitation grants an attacker full Remote Code Execution on the backend server as the service account running the AutoGPT Platform process. This enables complete server compromise, exfiltration of all user data, credentials, and API keys stored in the database, access to environment variables containing cloud credentials and secrets, lateral movement to connected infrastructure (Redis, PostgreSQL, cloud services), and installation of persistent backdoors. The impact extends beyond the directly vulnerable system to any downstream infrastructure reachable from the compromised server (GitHub Advisory).

Exploitability

The vulnerability requires only a low-privilege authenticated account; in default self-hosted deployments where Supabase signup is enabled, an attacker can self-register at no cost. The disabled block's UUID (45e78db5-03e9-447f-9395-308d712f5f08) is hardcoded in the public open-source repository, making target identification trivial. A proof-of-concept is included in the official security advisory. The EPSS score is approximately 0.096% (low automated exploitation probability at time of publication), and there is no current evidence of in-the-wild exploitation or CISA KEV listing (GitHub Advisory, Feedly).

Exploitation steps

  1. Account Registration: Register a free account on the target AutoGPT Platform instance (self-hosted with Supabase signup enabled) or use an existing account if signup is disabled.
  2. Obtain Session Credentials: Log into the web UI to obtain a session cookie, or use the main API to mint an API key with EXECUTE_BLOCK permission via POST /api-keys.
  3. Craft Malicious Payload: Prepare a Python class inheriting from Block that executes arbitrary OS commands (e.g., via subprocess.check_output). The class must contain a UUID in its id field and a class name matching class <Name>(Block):.
  4. Invoke the Disabled Block via Main API: Send a POST request to the block execution endpoint with the hardcoded UUID and the malicious code as the code parameter:
curl -X POST "https://<target>/api/blocks/45e78db5-03e9-447f-9395-308d712f5f08/execute" \
  -H "Cookie: session=<session_token>" \
  -H "Content-Type: application/json" \
  -d '{"code": "<malicious_python_code>"}'
  1. Alternative — External API Route: Mint an API key with EXECUTE_BLOCK permission, then call POST /external-api/v1/blocks/45e78db5-03e9-447f-9395-308d712f5f08/execute with the same payload.
  2. Code Written and Executed: The BlockInstallationBlock.run() method writes the attacker's Python code to backend/blocks/<uuid>.py on the server filesystem and immediately imports and executes it via __import__(), achieving RCE.
  3. Post-Exploitation: Use the RCE to establish a reverse shell, exfiltrate database credentials and environment variables, or install a persistent backdoor (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /api/blocks/45e78db5-03e9-447f-9395-308d712f5f08/execute or /external-api/v1/blocks/45e78db5-03e9-447f-9395-308d712f5f08/execute; outbound connections from the backend server to unknown external IPs (reverse shell activity).
  • File System: Unexpected .py files appearing in the autogpt_platform/backend/backend/blocks/ directory with UUID-formatted filenames (e.g., aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee.py); newly created Python files containing subprocess, os.system, or network socket calls.
  • Logs: API access logs showing POST requests to the block execution endpoints with the disabled block UUID 45e78db5-03e9-447f-9395-308d712f5f08; Python import errors or tracebacks in application logs related to dynamically loaded block modules; unexpected API key creation events (POST /api-keys) followed immediately by external API block execution calls.
  • Process: Unusual child processes spawned by the Python/uvicorn backend process (e.g., bash, sh, curl, wget, python3 with suspicious arguments); unexpected network listeners or connections initiated by the backend service account.

Mitigation and workarounds

Upgrade AutoGPT Platform to version autogpt-platform-beta-v0.6.44 or later, which adds an explicit disabled flag check to both execution endpoints (returning HTTP 403 for disabled blocks). Note that at the time of advisory publication, the fix was available in the GitHub release but had not yet been published to the PyPI registry — verify the installed package version carefully. As an interim workaround for hosted deployments, disable user self-registration (Supabase signup) to prevent unauthenticated account creation, and audit all execution logs for requests referencing the block UUID 45e78db5-03e9-447f-9395-308d712f5f08 (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher rahulgovind and published via GitHub's security advisory program on January 29, 2026. A brief write-up was published by Infinit Security at infinitsec.net covering the RCE via disabled block execution. The CVE received automated tracking coverage from vulnerability aggregators including VulnDB, CIRCL, and Vulners shortly after disclosure. No major vendor statements beyond the official advisory or significant threat actor attribution have been reported (GitHub Advisory, Infinit Security).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management