PT-2025-12282 · Unknown · Transformeroptimus/Superagi
Published
2025-03-20
·
Updated
2025-07-29
·
CVE-2024-9431
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
transformeroptimus/superagi version v0.0.14
Description
The issue is related to improper privilege management. After logging into the system, users can change the passwords of other users, which could lead to account takeover.
Recommendations
For version v0.0.14, consider restricting access to the password change functionality to prevent unauthorized modifications until a fix is available. As a temporary workaround, limit user privileges to minimize the risk of exploitation.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Transformeroptimus/Superagi