CVE-2024-1880
Last modified
CVE-2024-1880 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versions up to v0.5.0. The vulnerability arises from the improper neutralization of special elements used in an OS command within the `_speech` method of the MacOSTTS class. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versions up to v0.5.0. The vulnerability arises from the improper neutralization of special elements used in an OS command within the `_speech` method of the MacOSTTS class. Specifically, the use of `os.system` to execute the `say` command with user-supplied text allows for arbitrary code execution if an attacker can inject shell commands. This issue is triggered when the AutoGPT instance is run with the `--speak` option enabled and configured with `TEXT_TO_SPEECH_PROVIDER=macos`, reflecting back a shell injection snippet. The impact of this vulnerability is the potential execution of arbitrary code on the instance running AutoGPT. The issue was addressed in version 5.1.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Agpt | Autogpt Classic | < 0.5.1 |
References
- https://huntr.com/bounties/4e742624-8771-4f3c-9634-3eaf33d6d58eExploit, Issue Tracking, Patch, Third Party Advisory
- https://huntr.com/bounties/4e742624-8771-4f3c-9634-3eaf33d6d58eExploit, Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-1880?
How severe is CVE-2024-1880?
How do I fix CVE-2024-1880?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-1874In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.…9.4
- CVE-2024-1875A vulnerability was found in SourceCodester Complaint Manage…8.8
- CVE-2024-1876A vulnerability was found in SourceCodester Employee Managem…9.8
- CVE-2024-1877A vulnerability was found in SourceCodester Employee Managem…8.8
- CVE-2024-1878A vulnerability was found in SourceCodester Employee Managem…8.8
- CVE-2024-1879A Cross-Site Request Forgery (CSRF) vulnerability in signifi…8.8
- CVE-2024-1881AutoGPT, a component of significant-gravitas/autogpt, is vul…9.8
- CVE-2024-1882This vulnerability allows an already authenticated admin use…7.2
- CVE-2024-1883This is a reflected cross site scripting vulnerability in th…6.1
- CVE-2024-1884This is a Server-Side Request Forgery (SSRF) vulnerability i…6.5
- CVE-2024-1885This vulnerability allows remote attackers to execute arbitr…9.8
- CVE-2024-1886 This vulnerability allows remote attackers to traverse th…8.8
Are you affected by CVE-2024-1880?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
