CVE-2026-30950 is an authenticated insecure direct object reference (IDOR) / authorization bypass vulnerability in AutoGPT autogpt-platform-backend affecting versions 0.6.36 through 0.6.50. The flaw is in the PATCH /api/chat/sessions/{session_id}/assign-user endpoint, which is intended to let a newly authenticated user claim an anonymous session. Although the route requires a valid JWT, it does not verify that the caller owns the target session before reassigning it. In the vulnerable code path, the service function assign_user_to_session retrieves the target session by calling the session lookup helper with user_id=None. The data access layer interprets user_id=None as a privileged or system context and skips the normal ownership filter, allowing any authenticated user who knows another user’s session_id to reassign that session to themselves. Successful exploitation enables takeover of the victim’s chat session, including access to message history and associated session context, and can lock the legitimate user out. The issue was patched in version 0.6.51.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a self-contained proof-of-concept for CVE-2026-30950 affecting AutoGPT Platform Backend. The main exploit is pocs/session_hijack.py, a Python script using requests to authenticate against Supabase/Kong, create and query chat sessions, and exploit a missing authorization check by sending PATCH /api/chat/sessions/{session_id}/assign-user with an attacker JWT. The exploit demonstrates that any authenticated user can take ownership of another user’s chat session if they know the session UUID, then read the session while the original owner is denied access. This is a real exploit, not just detection logic. Repository structure is small and purpose-built: README.md documents the vulnerability, impact, and usage; pocs/session_hijack.py is the exploit entry point; setup/setup.sh bootstraps a vulnerable AutoGPT lab by cloning Significant-Gravitas/AutoGPT at tag autogpt-platform-beta-v0.6.50, starting the required Docker Compose services, creating attacker/victim users, and validating the vulnerable route; setup/docker-compose.override.yml isolates the lab under custom project/network/container names and exposes only ports 58000 and 58006; setup/teardown.sh removes the environment. The exploit targets authenticated web/API access rather than local code execution and provides session hijacking, message disclosure, and victim lockout, but does not deliver arbitrary code execution or a shell.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.