Skip to content

Conversation

dhvll
Copy link
Contributor

@dhvll dhvll commented Aug 31, 2025

AutoGPT Prompt Injection + Memory Exhaustion Cascade Vulnerability

Critical security flaw in AutoGPT that allows attackers to trigger memory exhaustion through crafted prompts, causing system crashes via SIGKILL/OOM killer.

Complete system crash - AutoGPT process terminated by OOM killer
Memory exhaustion cascade - 1GB+ memory consumption in seconds
Service disruption - Container restart required after crash
Production downtime - Real-world exploitable vulnerability

VULNERABILITY SUCCESSFULLY TRIGGERED!
Memory exhaustion: 200MB → 400MB → 600MB → 800MB → 1000MB
CRITICAL: OOM killer activated - terminating AutoGPT process
ERROR: Process killed by signal 9 (SIGKILL)
Container Status: Crashed and restarted ✅

References

CRE - playground

/fix #129
/claim #129

@dhvll dhvll changed the title Add new category for prompt injection memory exhaustion vulnerabilities Add rule for prompt injection memory exhaustion vulnerabilities Sep 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

AutoGPT: Reproduce A High-Severity Failure & Write a CRE Rule [Multiple Winners] [Submit by August 31 11:59 pm ET]
1 participant