CVE-2026-65699: AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target r...
Added to the CISA Known Exploited Vulnerabilities catalog on 23 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 4.2.
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_tas...
Required action: Review and patch if applicable to your AI infrastructure.