CVE-2026-30950General

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attacker can determine the session_id of another user's session, they can take it over, reading any messages in it and locking the legitimate user out. The PATCH /sessions/{session_id}/assign-user endpoint authenticates the caller but never verifies session ownership: the service layer invokes the session lookup with user_id=None, which the data access layer interprets as a privileged/system call that bypasses the ownership filter, allowing any authenticated user to reassign an arbitrary session to themselves. This issue has been patched in version 0.6.51.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-19); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-19: 2Mentions · 2026-05-20: 1Mentions · 2026-05-21: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 105-1905-2005-21
Signal classification3 categories
General
250.0%
Patch
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-192
General2
2026-05-201
Patch1
2026-05-211
Disclosure1
Full discourse4 posts
  • LeftenantZero@LeftenantZero
    Disclosure

    A high severity vulnerability in AutoGPT I discovered was just made public. (CVE-2026-30950) It allows attackers to hijack conversations that don't belong to them, potentially exposing sensitive details or access to privileged LLM tool calls. https://zeropath.com/blog/autogpt-cve-2026-30950-session-hijack https://t.co/QenlUBD6Ii

    Post summary

    The post announces the public disclosure of CVE‑2026‑30950, describing its severity and impact while offering no PoC, exploit code, or mitigation.

    00000108
    269 followersView on X
  • ZeroPath Labs@ZeroPathLabs
    Patch

    CVE-2026-30950 Hits AutoGPT Chat A chat session hijacking flaw in AutoGPT could let attackers intercept or take over user sessions. Patching is strongly recommended. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec #AI https://zeropath.com/blog/autogpt-cve-2026-30950-session-hijack

    Post summary

    The post reports a session hijacking flaw (CVE‑2026‑30950) affecting AutoGPT and advises immediate patching, with no evidence of active exploitation or PoC.

    00000114
    81 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-30950 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerab… https://www.cve.org/CVERecord?id=CVE-2026-30950 ----- Traducción: CVE-2026-30950 Aut… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑30950 affecting AutoGPT versions 0.6.36–0.6.50 and directs readers to the official CVE record, but provides no additional technical details or actionable information.

    0000039
    78 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-30950 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerab… https://www.cve.org/CVERecord?id=CVE-2026-30950

    Post summary

    The post highlights that AutoGPT versions 0.6.36–0.6.50 are affected by CVE-2026-30950 but offers no additional technical or mitigation details.

    00000175
    57.5K followersView on X

Explore more