superagi records
13 published records for vendor superagi.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-304 Missing Critical Step in Authentication1
- CWE-359 Exposure of Private Personal Information to an Unauthorized Actor1
- CWE-1230 Exposure of Sensitive Information Through Metadata1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-21552No exploit | All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function.CWE-94 | Critical9.8 | — | 0.6% | Jul 22, 2024 |
35Monitor | CVE-2024-9415No exploit | Path Traversal in transformeroptimus/superagisuperagi · superagi · CWE-22 | High8.8 | — | 1.5% | Mar 20, 2025 |
35Monitor | CVE-2024-9439No exploit | Remote Code Execution in transformeroptimus/superagisuperagi · superagi · CWE-94 | High8.8 | — | 1.2% | Mar 20, 2025 |
35Monitor | CVE-2024-12048No exploit | IDOR Vulnerability in transformeroptimus/superagisuperagi · superagi · CWE-304 | High8.8 | — | 0.7% | Mar 20, 2025 |
35Monitor | CVE-2024-9431No exploit | Improper Privilege Management in transformeroptimus/superagisuperagi · superagi · CWE-620 | High8.8 | — | 0.6% | Mar 20, 2025 |
30Monitor | CVE-2024-9437No exploit | Unauthenticated Denial of Service in transformeroptimus/superagisuperagi · superagi · CWE-770 | High7.5 | — | 0.8% | Mar 20, 2025 |
30Monitor | CVE-2024-10267No exploit | Information Disclosure in transformeroptimus/superagisuperagi · superagi · CWE-359 | High7.5 | — | 0.6% | Mar 20, 2025 |
30Monitor | CVE-2023-48055No exploit | SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations.superagi · superagi · CWE-798 | High7.5 | — | 0.4% | Nov 16, 2023 |
26Monitor | CVE-2024-9447No exploit | Exposure of Sensitive Information in transformeroptimus/superagisuperagi · superagi · CWE-1230 | Medium6.5 | — | 0.6% | Mar 20, 2025 |
26Monitor | CVE-2024-9418No exploit | Insufficiently Protected Credentials in transformeroptimus/superagisuperagi · superagi · CWE-256 | Medium6.5 | — | 0.6% | Mar 20, 2025 |
26Monitor | CVE-2025-51472No exploit | Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python superagi · superagi · CWE-77 | Medium6.5 | — | 0.4% | Jul 22, 2025 |
20Monitor | CVE-2025-51475No exploit | Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to ovesuperagi · superagi · CWE-22 | Medium5.0 | — | 0.8% | Jul 22, 2025 |
8Monitor | CVE-2025-6280No exploit | TransformerOptimus SuperAGI EmailToolKit read_email.py download_attachment path traversalsuperagi · superagi · CWE-22 | Low2.0 | — | 0.7% | Jun 19, 2025 |
- CVE-2024-2155239Monitor
All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function.
CriticalCVSS 9.8No exploitEPSS 1%Jul 22, 2024
- CVE-2024-941535Monitor
Path Traversal in transformeroptimus/superagi
HighCVSS 8.8No exploitEPSS 1%superagi · superagiMar 20, 2025
- CVE-2024-943935Monitor
Remote Code Execution in transformeroptimus/superagi
HighCVSS 8.8No exploitEPSS 1%superagi · superagiMar 20, 2025
- CVE-2024-1204835Monitor
IDOR Vulnerability in transformeroptimus/superagi
HighCVSS 8.8No exploitEPSS 1%superagi · superagiMar 20, 2025
- CVE-2024-943135Monitor
Improper Privilege Management in transformeroptimus/superagi
HighCVSS 8.8No exploitEPSS 1%superagi · superagiMar 20, 2025
- CVE-2024-943730Monitor
Unauthenticated Denial of Service in transformeroptimus/superagi
HighCVSS 7.5No exploitEPSS 1%superagi · superagiMar 20, 2025
- CVE-2024-1026730Monitor
Information Disclosure in transformeroptimus/superagi
HighCVSS 7.5No exploitEPSS 1%superagi · superagiMar 20, 2025
- CVE-2023-4805530Monitor
SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations.
HighCVSS 7.5No exploitEPSS 0%superagi · superagiNov 16, 2023
- CVE-2024-944726Monitor
Exposure of Sensitive Information in transformeroptimus/superagi
MediumCVSS 6.5No exploitEPSS 1%superagi · superagiMar 20, 2025
- CVE-2024-941826Monitor
Insufficiently Protected Credentials in transformeroptimus/superagi
MediumCVSS 6.5No exploitEPSS 1%superagi · superagiMar 20, 2025
- CVE-2025-5147226Monitor
Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python
MediumCVSS 6.5No exploitEPSS 0%superagi · superagiJul 22, 2025
- CVE-2025-5147520Monitor
Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to ove
MediumCVSS 5.0No exploitEPSS 1%superagi · superagiJul 22, 2025
- CVE-2025-62808Monitor
TransformerOptimus SuperAGI EmailToolKit read_email.py download_attachment path traversal
LowCVSS 2.0No exploitEPSS 1%superagi · superagiJun 19, 2025