Vulnerabilities
12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-51472 +1 in the same advisory: …51475 | Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious v Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, which are evaluated using eval() without validation during template loading or updates. NVD description · AI analysis pending | 6.5 group max | <1% | PoC ×2 |
| — | |
| CVE-2025-6280 | A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function download_attachment of the file SuperAGI/superagi/helper/read_email.py of the component EmailToolKit. The manipulation of the argument filename leads to path traversal. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 2.0 | <1% | PoC |
| — | |
| CVE-2024-9415 | A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to the server, potentially leading to remote code execution or overwriting any file on the server. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — | |
| CVE-2023-48055 | SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and communications. NVD description · AI analysis pending | 7.5 | <1% |
| — |