← CVEs and Advisories

CVE-2026-33234

Significant-Gravitas/AutoGPT · Severity Medium (CVSS 5.0) · Discovered by Pavan Nallamothu

The SendEmailBlock accepted a user-controlled SMTP server, allowing server-side request forgery that bypassed the IP blocklist and reached internal network services.

Summary

SSRF via a user-controlled SMTP server, bypassing the IP blocklist.

References

cve.org record · GitHub Security Advisory GHSA-4jwj-6mg5-wrwf