Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation
Vulnerability Description
AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_task_count functions look up the target AgentRun using the client-supplied run_id without confirming the run belongs to the requesting user, enabling an attacker who obtains a valid run_id to corrupt task history, exhaust the per-run loop budget, and drive LLM costs against the victim's run.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Reworkd AgentGPT 授权问题漏洞
Vulnerability Description
Reworkd AgentGPT是美国Reworkd公司的一个AI智能体开发平台。 Reworkd AgentGPT 1.0.0及之前版本存在授权问题漏洞,该漏洞源于用户可控密钥的授权绕过问题,允许认证用户在请求体中提供目标run_id而不进行所有权验证,从而导致攻击者能够附加任务到其他用户的agent运行,破坏任务历史、耗尽每运行循环预算并增加LLM成本。
CVSS Information
N/A
Vulnerability Type
N/A