CVE-2026-30950: AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hij...

Added to the CISA Known Exploited Vulnerabilities catalog on 18 May 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 7.1.

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attacker can determine the session_id of another user's session...

Required action: Review and patch if applicable to your AI infrastructure.