PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-32425 Significant-Gravitas CVE debrief

CVE-2025-32425 is a medium-severity denial-of-service vulnerability in AutoGPT Platform, published 2026-05-13 and last modified 2026-05-26. The issue stems from unbounded container log growth in Docker deployments: execution output is captured to stdout/stderr and stored as container logs without size limits. Under high user access volume, logs can exhaust server disk resources, causing DoS. The vulnerability affects versions prior to 0.6.32; the fix in autogpt-platform-beta-v0.6.32 implements log size constraints. CVSS 4.0 vector indicates local attack vector with low attack complexity and low availability impact. The root cause maps to CWE-770 (Allocation of Resources Without Limits or Throttling).

Vendor
Significant-Gravitas
Product
AutoGPT
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-13
Original CVE updated
2026-09-30
Advisory published
2026-05-13
Advisory updated
2026-09-30

Who should care

Organizations running AutoGPT Platform in containerized/Docker deployments, particularly those with high user concurrency or production workloads where disk exhaustion would impact availability.

Technical summary

The AutoGPT Platform records execution output to console (stdout/stderr), which Docker captures as container logs. Prior to version 0.6.32, no log size limits were enforced during container deployment. Sustained high user access volumes generate unchecked log growth, leading to disk resource exhaustion and denial of service. The fix in version 0.6.32 introduces log size constraints to prevent unbounded growth.

Defensive priority

medium

Recommended defensive actions

  • Upgrade AutoGPT Platform to version 0.6.32 or later to obtain log size limiting controls
  • Review Docker logging configuration in container deployments to implement log rotation and size limits
  • Monitor disk utilization on AutoGPT Platform servers for anomalous log growth
  • Apply resource quotas and log retention policies at the container orchestration level as defense in depth

Evidence notes

Official CVE record and NVD entry confirm vulnerability details. GitHub Security Advisory GHSA-vw3v-whvp-33v5 provides vendor acknowledgment and mitigation guidance. Commit 57a06f70883ce6be18738c6ae8bb41085c71e266 contains the patch. Source code references show logging configuration and Docker Compose platform deployment settings.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-32425 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-32425

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-32425 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32425

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc48327b3124549543b45d933d16f622d2/autogpt_platform/autogpt_libs/autogpt_libs/logging/config.py

    [email protected] - Product

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Significant-Gravitas/AutoGPT/blob/62361ccc48327b3124549543b45d933d16f622d2/autogpt_platform/docker-compose.platform.yml

    [email protected] - Product

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/Significant-Gravitas/AutoGPT/commit/57a06f70883ce6be18738c6ae8bb41085c71e266

    [email protected] - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/Significant-Gravitas/AutoGPT/security/advisories/GHSA-vw3v-whvp-33v5

    [email protected] - Exploit, Mitigation, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.