Junglewise Threat Intelligence

CVE-2026-65699: reworkd AgentGPT authorization bypass in Agent task creation

CVE-2026-65699 · Severity: medium · CVSS 4.2 · Published 2026-07-23

Executive brief

AgentGPT, a platform for deploying autonomous AI agents, is vulnerable to an authorization flaw that allows one user to interfere with another user's AI tasks. If an attacker obtains a specific identifier for another user's active session, they can inject unauthorized tasks into that session. This can lead to corrupted task histories, the exhaustion of the victim's processing limits, and increased costs for the victim's AI service usage.

Technical details

AgentGPT through version 1.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the AgentCRUD.create_task and validate_task_count functions. The application performs a database lookup for an AgentRun using a client-supplied run_id without verifying that the authenticated user owns that specific run. An attacker with a valid session and knowledge of a victim's UUIDv4 run_id can submit requests to endpoints like /api/agent/execute to inject tasks. This allows the attacker to corrupt task history, exhaust the victim's per-run loop budget, and incur LLM API costs on the victim's behalf. The vulnerability is mitigated by the fact that run_ids are unguessable UUIDs not normally exposed to other users. The project was archived in January 2026 and may not receive a formal patch.

Affected products

  • reworkd AgentGPT <= 1.0.0

Timeline

  • 2026-01-28: other: Project archived by owner
  • 2026-07-23: disclosed: Vulnerability disclosed by researcher George Chen
  • 2026-07-23: advisory

References