Remote Code Execution in transformeroptimus/superagi
Vulnerability Description
SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters, which are then fed to the eval function without any sanitization or checks in place. This vulnerability can lead to full system compromise.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9439
Credits & Attribution
No credits recorded in the NVD database.
More from transformeroptimus
View All →Affected Vendor
transformeroptimus
View all reports →