6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of the authorisation method used.
Basic Information
ID
CVE-2025-41023
Source
INCIBE
Published
Feb 19, 2026 at 08:50
Affected Product
Vendor
Thesamur
Product
AutoGPT
Version
All versions
Affected Versions
Thesamur AutoGPT All versions