How Cal.com Rebuilt AppSec After Going Closed Source
How Cal.com consolidated noisy security tooling into one continuous, context-aware pull request security program with Gecko.
Gecko Security
There is an authorization bypass vulnerability in the external API that allows authenticated users to access execution results from other users’ graph executions. The vulnerability exists in the get_graph_execution_results endpoint, which validates that the requesting user can access the specified graph but fails to validate ownership of the execution ID parameter.
The endpoint performs proper authorization for the graph_id parameter by calling get_graph() with the authenticated user’s ID, ensuring the user owns or has access to the graph. However, it then directly queries execution data using the user-supplied graph_exec_id without validating that this execution belongs to the authorized graph or the requesting user. Notably, the internal API endpoint /graphs/{graph_id}/executions/{graph_exec_id} implements the correct authorization pattern, performing both execution ownership validation and graph relationship verification.
This IDOR vulnerability allows attackers to access sensitive execution data including input parameters (potentially containing API keys and credentials), output results, and proprietary workflow logic from any user’s graph executions, provided they can discover the target execution UUID.
Source: User-controlled graph_exec_id parameter in URL path /graphs/{graph_id}/executions/{graph_exec_id}/results
Call Chain:
get_graph_execution_results() function in autogpt_platform/backend/backend/server/external/routes/v1.py:115 processes external API requestgraph_db.get_graph(graph_id, user_id=api_key.user_id) validates user access to graph_id (authorization passes for attacker’s graph)execution_db.get_node_executions(graph_exec_id) called with user-controlled execution ID at line 123get_node_executions() at autogpt_platform/backend/backend/data/execution.py:728 with where clause {“agentGraphExecutionId”: graph_exec_id} - no user validationNodeExecutionResult.from_db(execution) constructs result objects containing victim’s execution dataPrerequisites:
Attack steps:
<code class="hljs language-bash">curl -X GET \
<span class="hljs-string">"https://platform.autogpt.co/api/graphs/ATTACKER_GRAPH_ID/executions/VICTIM_EXECUTION_UUID/results"</span> \
-H <span class="hljs-string">"X-API-Key: ATTACKER_API_KEY"</span>
</code>Result: Server validates access to ATTACKER_GRAPH_ID (succeeds) but returns execution data from VICTIM_EXECUTION_UUID containing sensitive input/output data, API keys, and proprietary workflow information.

Artemiy Malyshau
Co-founder & CTO
Artemiy served in an elite unit of the Austrian Cyber Forces, defending national infrastructure He was then the first employee at a government-backed cybersecurity research group, where he led security projects for Interpol and national governments. At Gecko he builds the platform trusted to sit inside Fortune 500 codebases, and holds it to the standard those governments taught him.
The latest news, technologies, and resources from our team.
How Cal.com consolidated noisy security tooling into one continuous, context-aware pull request security program with Gecko.
Gecko Security
Authorization bypass in n8n’s dynamic-credentials OAuth endpoints allows any authenticated user to operate on another user’s OAuth credential by supplying its ID, enabling unauthorized OAuth rebinding and revocation.
Artemiy Malyshau
An IDOR vulnerability in n8n’s public variables API allows authenticated users to read project variables outside their authorized scope, exposing secrets across project boundaries.
Artemiy Malyshau
Learn API scanning for automated security testing. Find vulnerabilities from broken authentication to business logic flaws in your endpoints.
Artemiy Malyshau
A complete guide to automated pentest tools and best practices. Learn what works, what doesn’t, and how to implement continuous security testing.
Artemiy Malyshau
Compare the best AI-powered application security testing tools. Find which tools detect business logic flaws and broken access control.
Artemiy Malyshau
Occasional updates, new content, and insights. No spam; unsubscribe anytime.