CVE Explorer
CVE-2026-26006
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. The autogpt before 0.6.32 is vulnerable to Regular Expression Denial of Service due to the use of regex at Code Extraction Block. The two Regex are used containing the corresponding dangerous patterns \s+[\s\S]*? and \s+(.*?). They share a common characteristic — the combination of two adjacent quantifiers that can match the same space character (\s). A
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"AutoGPT","vendor":"Significant-Gravitas","versions":[{"status":"affected","version":">= 0.4.0, < 0.6.32"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e4236a60f35705d23eb68f56fa1507025e46a87f1e31155ea723a80d23fbc686 · sha256:225e26451a766555… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e4236a60f35705d23eb68f56fa1507025e46a87f1e31155ea723a80d23fbc686 · sha256:225e26451a766555… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1333","description":"CWE-1333: Inefficient Regular Expression Complexity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e4236a60f35705d23eb68f56fa1507025e46a87f1e31155ea723a80d23fbc686 · sha256:225e26451a766555… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/Significant-Gravitas/AutoGPT/blob/master/autogpt_platform/backend/backend/blocks/code_extraction_block.py#L106-L109","tags":["x_refsource_MISC"],"url":"https://github.com/Significant-Gravitas/AutoGPT/blob/master/autogpt_platform/backend/backend/blocks/code_extraction_block.py#L106-L109"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e4236a60f35705d23eb68f56fa1507025e46a87f1e31155ea723a80d23fbc686 · sha256:225e26451a766555… · /containers/cna/references/2
{"name":"https://github.com/Significant-Gravitas/AutoGPT/blob/master/autogpt_platform/backend/backend/blocks/code_extraction_block.py#L86-L96","tags":["x_refsource_MISC"],"url":"https://github.com/Significant-Gravitas/AutoGPT/blob/master/autogpt_platform/backend/backend/blocks/code_extraction_block.py#L86-L96"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e4236a60f35705d23eb68f56fa1507025e46a87f1e31155ea723a80d23fbc686 · sha256:225e26451a766555… · /containers/cna/references/3
{"name":"https://github.com/Significant-Gravitas/AutoGPT/commit/57a06f70883ce6be18738c6ae8bb41085c71e266","tags":["x_refsource_MISC"],"url":"https://github.com/Significant-Gravitas/AutoGPT/commit/57a06f70883ce6be18738c6ae8bb41085c71e266"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e4236a60f35705d23eb68f56fa1507025e46a87f1e31155ea723a80d23fbc686 · sha256:225e26451a766555… · /containers/cna/references/1
{"name":"https://github.com/Significant-Gravitas/AutoGPT/releases/tag/autogpt-platform-beta-v0.6.32","tags":["x_refsource_MISC"],"url":"https://github.com/Significant-Gravitas/AutoGPT/releases/tag/autogpt-platform-beta-v0.6.32"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e4236a60f35705d23eb68f56fa1507025e46a87f1e31155ea723a80d23fbc686 · sha256:225e26451a766555… · /containers/cna/references/4
{"name":"https://github.com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-m2wr-7m3r-p52c","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-m2wr-7m3r-p52c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e4236a60f35705d23eb68f56fa1507025e46a87f1e31155ea723a80d23fbc686 · sha256:225e26451a766555… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.