{"id":"CVE-2026-65699","summary":"AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation","details":"AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_task_count functions look up the target AgentRun using the client-supplied run_id without confirming the run belongs to the requesting user, enabling an attacker who obtains a valid run_id to corrupt task history, exhaust the per-run loop budget, and drive LLM costs against the victim's run.","modified":"2026-08-12T03:51:19.612496305Z","published":"2026-07-23T16:59:46.107Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65699.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65699.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65699"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/agentgpt-authorization-bypass-via-agent-task-creation"},{"type":"PACKAGE","url":"https://github.com/reworkd/AgentGPT"},{"type":"EVIDENCE","url":"https://github.com/geo-chen/oss/blob/main/AgentGPT.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/reworkd/agentgpt","events":[{"introduced":"0"},{"last_affected":"e96caae9dddad89a2043a74017935c4babe80930"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.0.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v.1.0.0","v.0.10.0-beta","v.0.9.5-beta","v.0.9.0-beta","v.0.7.0-beta","v.0.6.0-beta","v.0.4.0-beta","v.0.3.0-beta","v.0.2.0-beta","v.0.1.0-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65699.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"}]}