CVE-2024-9447 is an information disclosure vulnerability in transformeroptimus/superagi, specifically affecting the latest version of SuperAGI. It allows any authenticated user to retrieve sensitive configuration details, including API keys, of any organization via the /get/organisation/ endpoint due to a lack of organization verification. Rated 6.5 MEDIUM (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), this vulnerability could lead to unauthorized service access and significant data breaches or financial loss. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.0.14CPE matchmatch criteria | cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.