PT-2026-33720 · Transformeroptimus · Superagi

Eric-Z

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6613

CVSS v3.1

6.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete agent/stop schedule/get schedule data of the file superagi/controllers/agent.py. The manipulation of the argument agent id leads to authorization bypass. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

IDOR

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-6613

Affected Products

Superagi