CVE 6.9 MEDIUM

Authentication bypass in AutoGPT de Thesamur_CVE-2025-41023

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of the authorisation method used.

Basic Information

ID CVE-2025-41023
Source INCIBE
Published Feb 19, 2026 at 08:50

Affected Product

Vendor Thesamur
Product AutoGPT
Version All versions
Affected Versions Thesamur AutoGPT All versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.