Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/chaitanyagarware/cve-2026-54519
Authentication & AuthorizationVulnerability AnalysisWeb SecurityLearning & EducationCurated ResourcesAI Security
GitHubchaitanyagarware/cve-2026-54519

CVE-2026-54519

Public advisory landing page for CVE-2026-54519: missing ownership checks in ai-agent-automation memory APIs enabling cross-user memory read and deletion. Links to GHSA, CVE.org, NVD, and OSV records.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View RepositoryWebsite
132 months agoNot yet reviewed

CVE-2026-54519

ai-agent-automation missing ownership checks in memory APIs allowed cross-user memory read and deletion.

Primary advisory: GHSA-qv97-83w4-ff86
Researcher credit: @chaitanyagarware

At a Glance

FieldValue
CVECVE-2026-54519
GHSAGHSA-qv97-83w4-ff86
ProjectvmDeshpande/ai-agent-automation
Packagebackend
Ecosystemnpm
SeverityHigh
CVSS8.8, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
WeaknessCWE-862
PublishedGitHub repository advisory: 2026-06-05
Patched versionv0.9.1
Public database statusGitHub repository advisory published; CVE.org, NVD, and OSV did not return records as of 2026-07-09

Summary

The backend memory APIs were authenticated but did not verify that the requested memory records belonged to the authenticated user. A user who knew or obtained another user's agentId or memory _id could query or delete memory records that belonged to a different account.

The affected controller was backend/src/controllers/memory.controller.js.

Affected Versions

PackageAffected
backend<= 0.8.0

Fixed Versions

PackageFixed
backendv0.9.1

Public Database Coverage

Additional Public Mentions Found

  • chaitanyagarware/chaitanyagarware profile README references this CVE/GHSA.
  • chaitanyagarware/chaitanyagarware.github.io references this CVE/GHSA.
  • No broader GitHub issue/repo search results were returned for the exact CVE/GHSA terms during the 2026-07-09 sweep.

Disclosure Note

This repository is a public index and portfolio landing page. It intentionally summarizes the vulnerability and links to authoritative records instead of copying full proof-of-concept exploit scripts.

Download Tool
SourceStatusLink
GitHub repository advisoryPublishedGHSA-qv97-83w4-ff86
CVE.orgNot indexed yetCVE detail
NVDNot indexed yetNVD detail
OSVNot indexed yetOSV lookup