AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation
Published Jul 23, 2026
2.3
LOWCVSS 4.0
EPSS 0.28%
Description
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_task_count functions look up the target AgentRun using the client-supplied run_id without confirming the run belongs to the requesting user, enabling an attacker who obtains a valid run_id to corrupt task history, exhaust the per-run loop budget, and drive LLM costs against the victim's run.
Affected products
-
- Version 0StatusaffectedConstraints<=1.0.0
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48330 Advisory
- https://github.com/geo-chen/oss/blob/main/AgentGPT.md technical-descriptionexploit
- https://www.vulncheck.com/advisories/agentgpt-authorization-bypass-via-agent-task-creation third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48330 | Advisory | |
| https://github.com/geo-chen/oss/blob/main/AgentGPT.md | technical-descriptionexploit | |
| https://www.vulncheck.com/advisories/agentgpt-authorization-bypass-via-agent-task-creation | third-party-advisory |
Change history (0)
No recorded changes yet.