A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to the server, potentially leading to remote code execution or overwriting any file on the server.
History

Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to the server, potentially leading to remote code execution or overwriting any file on the server.
Title Path Traversal in transformeroptimus/superagi
Weaknesses CWE-22
References
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:09:06.219Z

Updated: 2025-03-20T18:58:16.596Z

Reserved: 2024-10-01T17:24:24.183Z

Link: CVE-2024-9415

cve-icon Vulnrichment

Updated: 2025-03-20T17:50:40.398Z

cve-icon NVD

Status : Received

Published: 2025-03-20T10:15:48.580

Modified: 2025-03-20T10:15:48.580

Link: CVE-2024-9415

cve-icon Redhat

No data.