What is CVE-2026-65699?
CVE-2026-65699: AgentGPT through version 1.0.0 contains an authorization bypass vulnerability. An authenticated user can attach tasks to another user's agent run by providing a target `run_id` in the request body without ownership verification. It is recommended to immediately update to the latest version.
Azərbaycanca: CVE-2026-65699: AgentGPT 1.0.0 və aşağı versiyalarında avtorizasiya bypass zəifliyi aşkar edilib. Autentifikasiya olunmuş istifadəçi sorğu gövdəsində hədəf `run_id` təqdim edərək, mülkiyyət yoxlaması olmadan başqa istifadəçinin agent işinə tapşırıq əlavə edə bilər. Dərhal versiyanı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What versions of AgentGPT are affected by CVE-2026-65699?
CVE-2026-65699 affects AgentGPT through version 1.0.0.
How can this authorization bypass be exploited?
An authenticated user can attach tasks to another user's agent run by providing a target `run_id` in the request body without ownership verification.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.