Information Exposure Affecting agpt package, versions [0,]


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-AGPT-9802316
  • published24 Apr 2025
  • disclosed14 Apr 2025
  • creditJoshua Rogers

Introduced: 14 Apr 2025

NewCVE-2025-31491  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

agpt is an An open-source attempt to make GPT-4 autonomous

Affected versions of this package are vulnerable to Information Exposure through the request.py wrapper. An attacker can intercept and misuse sensitive information by exploiting the improper handling of HTTP headers and cookies during redirects.

Note: The standard requests library does not suffer from this vulnerability. When a redirect occurs, headers such as Authorization and Proxy-Authorization are not sent across origins, and cookies are managed securely using the standard cookiejar format.

CVSS Base Scores

version 4.0
version 3.1