CVE-2025-41023
Awaiting Analysis
Awaiting Analysis - Queue
Authentication Bypass in Thesamur AutoGPT Enables Full Access
Publication date: 2026-02-19
Last updated on: 2026-02-19
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of the authorisation method used.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| thesamur | autogpt | * |
| thesamur | auto_gpt | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |