Database/AI/ML frameworks & serving
AutoGPT Platform: unbounded container logs fill the host disk and take the service down
Impact
The AutoGPT Platform containers write execution output to stdout/stderr with no logging limit configured in the compose deployment, so Docker retains everything. Enough agent activity - organic or driven by a user hammering the endpoint - grows the json-file logs until the host disk is exhausted and the service, plus anything else sharing that filesystem, stops. On a node that also holds model weights or a container image cache on the same volume, a full disk is a node-level outage rather than a single-service one. Availability impact only; no data exposure.
Who can reach it
Any user who can trigger agent executions against the platform. No authentication bypass and no host access needed; the attack is volume of ordinary use.
What to do
Upgrade to autogpt-platform-beta-v0.6.32 or later and redeploy the compose stack. The same exposure can be mitigated independently of the version by setting per-container log limits (max-size/max-file) or a non-local logging driver, and by putting container logs on a volume separate from model and image storage. A container recreate, not a node reboot.
References
Related entries
- JupyterLab: stored XSS from javascript: URLs in extension metadata shown by Extension ManagerCVE-2026-67338 · JupyterLab Extension Manager (package metadata URL protocol validation)Medium
- TensorFlow Lite (flatbuffer models): Out-of-bounds via duplicate tensor indices in flatbuffer modelsCVE-2020-15211 · TensorFlow Lite (flatbuffer models)Medium
- Intel Extension for PyTorch: unsafe deserialization of untrusted data allows local privilege escalationCVE-2026-35502 · Intel Extension for PyTorch (untrusted deserialization)Medium
- diffusers (shard file loader): Path traversal in `_get_checkpoint_shard_files`CVE-2026-65920 · diffusers (shard file loader)Medium
- vLLM: derender endpoints process caller-supplied response objects before limits, exhausting CPU and memoryCVE-2026-71486 · vLLM OpenAI-compatible server (/v1/completions/derender and /v1/chat/completions/derender)Medium
- AMD graphics driver - dynamic power management (DPM) array index validation: An unvalidated array index in the driver'sCVE-2023-31306 · AMD graphics driver - dynamic power management (DPM) array index validationLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.