Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

AgentGPT authorization bypass allows unauthorized task attachment

AgentGPT through version 1.0.0 contains an authorization bypass vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id without ownership verification. Attackers can corrupt task history, exhaust loop budgets, and drive LLM costs against victims.

Disclosed 23 July 2026 · Record updated 13 September 2026

Impact

Authenticated attackers can attach tasks to other users' agent runs, corrupting task history, exhausting per-run loop budgets, and increasing LLM costs for victims.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-65699