CVE-2026-55237CWE-601CWE-87

AutoGPT SignUp Page has DOM-Based XSS and Open Redirect

High · published June 18, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
24.4
In the wild
Unconfirmed
What it is

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), which is passed to `router.push`. An attacker can craft a malicious link that, when opened by an authenticated user, performs a client-side redirect and executes arbitrary JavaScript in the context of their browser. This could lead to credential theft, internal network pivoting, and unauthorized actions performed on behalf of the victim. Version 0.6.62 patches the issue.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00319 · 24.4th percentile
Weaknesses
CWE-601 · URL Redirection to Untrusted Site ('Open Redirect'); CWE-87 · Improper Neutralization of Alternate XSS Syntax
Published
2026-06-18T16:21Z
EPSS history
Timeline
  • 18 JUN 16:21Z
    AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
    cvelistv5