HIGH🇵🇱 Wersja polska

CVE-2024-9439

CVSS 8.8v3.0pub. 2025-03-20upd. 2025-07-14

SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters, which are then fed to the eval function without any sanitization or checks in place. This vulnerability can lead to full system compromise.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Superagi

    APP
    Superagi
    0.0.14
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-9431HIGH8.8same product

In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. Af...

CVE-2024-12048HIGH8.8same product

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14...

CVE-2024-9415HIGH8.8same product

A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version ...

CVE-2024-10267HIGH7.5same product

An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attack...

CVE-2024-9437HIGH7.5same product

SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability...