Superagi develops an autonomous AI agent framework that sits in development and deployment pipelines for AI-driven automation workflows. Its vulnerability profile concentrates in the core Superagi product and centers on implementation gaps typical of early-stage AI infrastructure: path traversal, inadequate resource throttling, authorization bypass through user-controlled parameters, and exposure of sensitive metadata and personal information. Defenders integrating this framework should apply strict input validation, implement resource limits, enforce role-based access controls, and audit metadata handling; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Superagi over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6280CRITICAL A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function download_attachment of the file SuperAGI/superagi | Jun 19, 2025 | 9.8 | 29 | NO | NO |
CVE-2024-9439HIGH SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters, which are then fed to the eva | Mar 20, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-9415HIGH A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary f | Mar 20, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-9431HIGH In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other u | Mar 20, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-12048HIGH An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple A | Mar 20, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-10267HIGH An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and p | Mar 20, 2025 | 7.5 | 21 | NO | NO |
CVE-2023-48055HIGH SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and communications. | Nov 16, 2023 | 7.5 | 21 | NO | NO |
CVE-2024-9437HIGH SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in the resource upload request, where appending characters, su | Mar 20, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-51472MEDIUM Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent templ | Jul 22, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-9447MEDIUM An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allo | Mar 20, 2025 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Superagi.
Media articles that mention a CVE ID that affects a product developed by Superagi — matched by CVE ID, not by vendor name.