PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-32422 Significant-Gravitas CVE debrief

CVE-2025-32422 AutoGPT Denial of Service via Unrestricted File Downloads. The vulnerability in AutoGPT versions prior to 0.6.63 allows for a Denial of Service (DoS) attack through the `StepThroughItemsBlock` feature, which can be exploited to repeatedly download files from `FileStoreBlock` without access time limits or disk space consumption limits. This can lead to disk space exhaustion, causing a DoS. AutoGPT users and administrators should assess exposure and prioritize remediation to prevent potential DoS attacks.

Vendor
Significant-Gravitas
Product
AutoGPT
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-18
Original CVE updated
2026-09-29
Advisory published
2026-06-18
Advisory updated
2026-09-29

Who should care

AutoGPT users and administrators should assess exposure and prioritize remediation to prevent potential DoS attacks. This includes reviewing system configurations, restricting access to the `StepThroughItemsBlock` feature, and implementing compensating controls for exposed systems. Security teams should verify that appropriate measures are in place to mitigate the vulnerability and monitor for excessive disk space consumption.

Why it matters

CVE-2025-32422 is a high-severity vulnerability in AutoGPT that can be exploited for Denial of Service (DoS) attacks. AutoGPT users and administrators should assess exposure, prioritize remediation, and implement compensating controls to prevent potential disk space exhaustion.

  • Potential Denial of Service (DoS) via disk space exhaustion
  • Need to verify and restrict access to the `StepThroughItemsBlock` feature
  • Requirement to upgrade to version 0.6.63 or later for patched functionality

Technical summary

The `StepThroughItemsBlock` feature in AutoGPT versions prior to 0.6.63 can be exploited to cause a Denial of Service (DoS) by repeatedly downloading files from `FileStoreBlock` without access time limits or disk space consumption limits. This vulnerability allows for disk space exhaustion, leading to a DoS attack. The issue is patched in version 0.6.63, which limits the exploitation of this feature. Affected AutoGPT users and administrators should assess exposure and prioritize remediation to prevent potential DoS attacks.

Defensive priority

High

Recommended defensive actions

  • Upgrade AutoGPT to version 0.6.63 or later
  • Implement monitoring for excessive disk space consumption
  • Restrict access to the `StepThroughItemsBlock` feature
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry describe a Denial of Service (DoS) vulnerability in AutoGPT versions prior to 0.6.63. The vulnerability is caused by the `StepThroughItemsBlock` feature, which can be used to repeatedly download files from `FileStoreBlock` without access time limits or disk space consumption limits. Evidence is based on CVE and NVD descriptions, with limitations on source-provided details.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-32422 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-32422

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-32422 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32422

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.