CVE-2026-30950 | Significant-Gravitas AutoGPT up to 0.6.50 Message assign-user authorization (GHSA-q58p-v9r9-7gqj)
A vulnerability, which was classified as problematic, has been found in Significant-Gravitas AutoGPT up to 0.6.50. Affected by this issue is some unknown functionality of the file /sessions/{session_id}/assign-user of the component Message Handler. This manipulation causes missing authorization.
The identification of this vulnerability is CVE-2026-30950. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.