CVE-2026-24780·Python vulnerability
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both main web API and external API) allow executing blocks by UUID without checking the `disabled` flag. Any authenticated user can execute the disabled `BlockInstallationBlock`, which writes arbitrary Python code to the server filesystem and executes it via `__import__()`, achieving Remote Code Execution. In default self-hosted deployments where Supabase signup is enabled, an attacker can self-register; if signup is disabled (e.g., hosted), the attacker needs an existing account. autogpt-platform-beta-v0.6.44 contains a fix.
- Severity
- high
- Software
- Python
- Fixed in
- 0.6.44
- Published
- 2026-01-29
Affected versions
From: 0.1.0
Until: 0.6.44
Fixed in: 0.6.44
How to fix this CVE
Upgrade AutoGPT Platform to version 0.6.44 or later to remediate this critical remote code execution vulnerability. The patch adds proper validation of the `disabled` flag on block execution endpoints, preventing execution of disabled blocks. Organizations running versions 0.1.0 through 0.6.43 should prioritize this update immediately, especially if Supabase signup is enabled for self-registration.
sudo dnf upgrade python3Defensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /api/v1/execute or POST /api/external/v1/execute with payload containing BlockInstallationBlock UUID and disabled=false override; OR requests to /api/v1/execute with block_uuid parameter pointing to disabled blocks followed by __import__() patterns in subsequent Python execution logsWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement WAF rules to block POST requests to /api/v1/execute and /api/external/v1/execute endpoints from users without elevated privileges; additionally, filter requests containing 'BlockInstallationBlock' in request body or parameters. Enforce strict rate limiting on these endpoints to slow reconnaissance attempts.How to check if you are affected
- Check AutoGPT Platform version: curl -s http://localhost:8000/api/version 2>/dev/null | grep -i version or inspect the installed package with pip show autogpt-platform
- Verify the `disabled` flag validation is enforced by reviewing the block execution logic in /backend/api/features/v1.py around line 1408-1424
- Search application logs for BlockInstallationBlock execution attempts: grep -r 'BlockInstallationBlock' /var/log/autogpt* or check request logs for POST requests to /api/v1/execute or /api/external/v1/execute endpoints
- Confirm remediation by upgrading to 0.6.44+ and verifying the patched code includes disabled block checks before execution
FAQ
What is CVE-2026-24780?
CVE-2026-24780 is a remote code execution vulnerability in AutoGPT Platform that allows authenticated users to execute disabled blocks containing arbitrary Python code, bypassing the `disabled` flag validation on block execution endpoints. This enables attackers to write and execute malicious Python code directly on the server.
Is CVE-2026-24780 being actively exploited?
No, CVE-2026-24780 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, the attack requires only standard authentication credentials, making it a significant risk if access controls are weak.
What versions of Python are affected by CVE-2026-24780?
This vulnerability affects AutoGPT Platform versions 0.1.0 through 0.6.43. The underlying Python runtime is not the vulnerable component; rather, the vulnerability exists in AutoGPT Platform's block execution logic that leverages Python's `__import__()` function unsafely.
How do I check if my server is vulnerable to CVE-2026-24780?
Run `pip show autogpt-platform | grep Version` to retrieve the installed version. If it shows any version from 0.1.0 to 0.6.43, your deployment is vulnerable. Additionally, check if the block execution endpoints validate the `disabled` flag by reviewing the source code at the GitHub references.
Does Defensia detect CVE-2026-24780?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If AutoGPT Platform is installed on a monitored server, CVE-2026-24780 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/Significant-Gravitas/AutoGPT/blob/master/autogpt_platform/backend/backend/api/external/v1/routes.py#L79-L93
- https://github.com/Significant-Gravitas/AutoGPT/blob/master/autogpt_platform/backend/backend/api/features/v1.py#L1408-L1424
- https://github.com/Significant-Gravitas/AutoGPT/blob/master/autogpt_platform/backend/backend/api/features/v1.py#L355-L395
- https://github.com/Significant-Gravitas/AutoGPT/blob/master/autogpt_platform/backend/backend/blocks/block.py#L15-L78
- https://github.com/Significant-Gravitas/AutoGPT/blob/master/autogpt_platform/backend/backend/data/block.py#L459
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-24780. Free for 1 server.
Get started free