PT-2026-33720 · Superagi · Superagi
Eric-Z
·
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-6613
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
TransformerOptimus SuperAGI versions prior to 0.0.15
Description
Remote authorization bypass occurs due to the manipulation of the
agent id argument. This issue affects the functions delete agent(), stop schedule(), and get schedule data() within the file 'superagi/controllers/agent.py'.Recommendations
Update to a version later than 0.0.14.
As a temporary workaround, restrict access to the functions
delete agent(), stop schedule(), and get schedule data() to minimize the risk of exploitation.Exploit
Fix
Improper Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Superagi