Researchers disclosed two high-severity flaws affecting AI tooling: CVE-2026-30950 in AutoGPT and CVE-2026-59950 in the Model Context Protocol (MCP) Python SDK. In AutoGPT, an authenticated insecure direct object reference in the /api/chat/sessions/{session_id}/assign-user endpoint allowed any logged-in user to reassign another user’s chat session with a single PATCH request if the session ID was known. The bug affected autogpt-platform-backend versions 0.6.36 through 0.6.50 and was fixed in 0.6.51; successful exploitation could expose full chat histories, pasted files, execution context, and credential-related metadata while also locking the victim out of the session.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
A report described CVE-2026-59950 as a high-severity cross-site WebSocket hijacking flaw affecting Model Context Protocol Python SDK server WebSocket handling. The write-up explained that a hijacked browser connection could send arbitrary JSON-RPC commands and also documented a mitigation using TransportSecurityMiddleware to validate hosts and origins.
Bugflation summarized a backfill of eight publicly corroborated vulnerabilities and included the AutoGPT session hijacking issue among them. The report said the vulnerabilities were corroborated by public CVE records, vendor advisories, and fixes, while noting ZeroPath's discovery attribution was self-reported.
ZeroPath Research publicly disclosed CVE-2026-30950, an authenticated IDOR vulnerability in AutoGPT that lets any logged-in user hijack another user's chat session if they know the session ID. The disclosure said affected versions were 0.6.36 through 0.6.50 and that exploitation could expose chat history, pasted files, and execution context while locking out the victim.
The AutoGPT project committed a fix for CVE-2026-30950 on 2026-03-08, addressing an authorization bypass in the chat session assignment endpoint. The patched release was identified as autogpt-platform-backend version 0.6.51.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcezeropath.com
Open sourcebugflation.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.