Unauthorized Data Access Vulnerability in AI Agent Automation by vmDeshpande
CVE-2026-54519
8.8HIGH
What is CVE-2026-54519?
AI Agent Automation allows for modular AI agent workflow automation. Prior to version 0.9.1, the platform’s memory handling APIs did not properly validate requests. Specifically, functions that manage memory data used identifiers provided by the request without confirming that the requester was allowed to access those identifiers. As a result, an authenticated attacker who gains access to another user's agentId or memory _id can view sensitive memory content, including conversation history and task data, as well as manipulate memory records. This vulnerability compromises data isolation between users, potentially leading to unauthorized data exposure and loss. The issue was rectified in version 0.9.1.
Affected Version(s)
ai-agent-automation < 0.9.1
