- EPSS 0.06%
- Veröffentlicht 22.07.2025 00:00:00
- Zuletzt bearbeitet 09.10.2025 16:08:29
Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handli...
CVE-2025-51472
- EPSS 0.05%
- Veröffentlicht 22.07.2025 00:00:00
- Zuletzt bearbeitet 09.10.2025 16:09:40
Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field...
CVE-2025-6280
- EPSS 0.13%
- Veröffentlicht 19.06.2025 21:27:45
- Zuletzt bearbeitet 09.07.2025 23:56:04
A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function download_attachment of the file SuperAGI/superagi/helper/read_email.py of the component EmailToolKit. The manipulation ...
CVE-2024-12048
- EPSS 0.12%
- Veröffentlicht 20.03.2025 10:11:27
- Zuletzt bearbeitet 18.07.2025 19:58:36
An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete other users...
CVE-2024-9437
- EPSS 0.18%
- Veröffentlicht 20.03.2025 10:10:40
- Zuletzt bearbeitet 15.10.2025 13:15:59
SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in the resource upload request, where appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP reques...
CVE-2024-9439
- EPSS 0.64%
- Veröffentlicht 20.03.2025 10:10:34
- Zuletzt bearbeitet 14.07.2025 20:16:31
SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters, which are then fed to the eval function without any sanitization or checks in place. This vulnerabi...
CVE-2024-9447
- EPSS 0.11%
- Veröffentlicht 20.03.2025 10:10:10
- Zuletzt bearbeitet 29.07.2025 19:04:30
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration detail...
CVE-2024-9431
- EPSS 0.06%
- Veröffentlicht 20.03.2025 10:09:46
- Zuletzt bearbeitet 15.10.2025 13:15:59
In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.
CVE-2024-10267
- EPSS 0.11%
- Veröffentlicht 20.03.2025 10:09:43
- Zuletzt bearbeitet 18.07.2025 19:57:36
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an email that i...
CVE-2024-9418
- EPSS 0.06%
- Veröffentlicht 20.03.2025 10:09:21
- Zuletzt bearbeitet 15.10.2025 13:15:59
In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account takeover.