Authorization Bypass Vulnerability in AgentGPT by Geo Chen
CVE-2026-65699
Key Information:
Badges
What is CVE-2026-65699?
AgentGPT version 1.0.0 has a critical flaw that permits authenticated users to bypass authorization checks by manipulating request parameters. This vulnerability allows users to attach tasks to agent runs belonging to other users without verifying ownership, posing a significant risk of task history corruption and excessive resource consumption against innocent users' runs. Attackers who exploit this weakness can gain unauthorized access to sensitive operations, leading to potential financial impacts and undermined user trust.
Affected Version(s)
AgentGPT 0 <= 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
