CyberRota Analysis
AI-GeneratedThe vulnerability in SuperAGI up to version 0.0.14 allows authenticated users to schedule agents from other organizations due to inadequate access control on the agent execution controller endpoint. This could lead to unauthorized manipulation of agents, potentially compromising sensitive operations and data across organizations. Organizations using SuperAGI should prioritize addressing this issue to prevent unauthorized access and ensure proper isolation between user data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization.