AutoGPT platform SSRF in SendDiscordFileBlock (CVE-2025-62616)
AutoGPT's SendDiscordFileBlock passed an unfiltered user-supplied URL to aiohttp.ClientSession().get, allowing server-side request forgery. The issue was patched in autogpt-platform-beta-v0.6.34.
Disclosed 4 February 2026 · Record updated 13 September 2026
Impact
Unfiltered URL input in a Discord file-sending block could be abused to make the server issue arbitrary requests (SSRF) in versions prior to autogpt-platform-beta-v0.6.34.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-62616
