GPU VulnDB

Database/AI/ML frameworks & serving

AutoGPT Platform: unbounded container logs fill the host disk and take the service down

CVSS 5.1CVE-2025-32425AI/ML frameworks & servingcurated

Impact

The AutoGPT Platform containers write execution output to stdout/stderr with no logging limit configured in the compose deployment, so Docker retains everything. Enough agent activity - organic or driven by a user hammering the endpoint - grows the json-file logs until the host disk is exhausted and the service, plus anything else sharing that filesystem, stops. On a node that also holds model weights or a container image cache on the same volume, a full disk is a node-level outage rather than a single-service one. Availability impact only; no data exposure.

Who can reach it

Any user who can trigger agent executions against the platform. No authentication bypass and no host access needed; the attack is volume of ordinary use.

What to do

Upgrade to autogpt-platform-beta-v0.6.32 or later and redeploy the compose stack. The same exposure can be mitigated independently of the version by setting per-container log limits (max-size/max-file) or a non-local logging driver, and by putting container logs on a volume separate from model and image storage. A container recreate, not a node reboot.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.