📦 Superagi

by Superagi

🔍 What is Superagi?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-9439

HIGH CVSS 8.8 Mar 20, 2025

SuperAGI's latest version contains a critical remote code execution vulnerability in the agent template update API. Attackers can inject malicious code through unsanitized parameters that get executed...

CVE-2024-9415

HIGH CVSS 8.8 Mar 20, 2025

A path traversal vulnerability in transformeroptimus/superagi version 0.0.14 allows attackers to upload arbitrary files to any location on the server. This can lead to remote code execution or file ov...

CVE-2024-9431

HIGH CVSS 8.8 Mar 20, 2025

This vulnerability in transformeroptimus/superagi v0.0.14 allows authenticated users to change other users' passwords after logging in, enabling account takeover. Any deployment using this vulnerable ...

CVE-2024-9437

HIGH CVSS 7.5 Mar 20, 2025

SuperAGI v0.0.14 is vulnerable to an unauthenticated Denial of Service attack where attackers can crash the service by sending specially crafted HTTP requests with malformed multipart boundaries. This...

CVE-2023-48055

HIGH CVSS 7.5 Nov 16, 2023

SuperAGI v0.0.13 uses a hardcoded encryption key, making all encrypted data vulnerable to decryption by attackers. This affects anyone using this version of SuperAGI, potentially exposing sensitive in...

CVE-2025-6280

MEDIUM CVSS 5.5 Jun 19, 2025

This critical vulnerability in TransformerOptimus SuperAGI allows attackers to perform path traversal attacks via the filename argument in the download_attachment function. This could enable unauthori...

CVE-2024-9447

MEDIUM CVSS 6.5 Mar 20, 2025

An information disclosure vulnerability in transformeroptimus/superagi allows authenticated users to access sensitive configuration details of any organization through the /get/organisation/ endpoint....