Authenticated Session Hijacking in AutoGPT by Significant Gravitas
CVE-2026-30950
7.1HIGH
What is CVE-2026-30950?
AutoGPT, a workflow automation platform, is vulnerable to an Authenticated Session Hijacking flaw that affects versions 0.6.36 through 0.6.50. This vulnerability allows an authenticated attacker to hijack another user's session if they can determine the session_id. The exploitation occurs through the PATCH /sessions/{session_id}/assign-user endpoint, which improperly authorizes session ownership, enabling a malicious user to read the legitimate user's messages and potentially lock them out. The issue has been addressed in version 0.6.51.
Affected Version(s)
AutoGPT >= 0.6.36, < 0.6.51
