CyberRota Analysis
AI-GeneratedSuperAGI versions up to v0.0.14 have an improper access control vulnerability in the agent execution controller, allowing remote authenticated attackers to manipulate agent execution records across different organizations. This flaw enables attackers to create or initiate execution records for agents that do not belong to their organization, potentially leading to unauthorized access and data manipulation. Organizations using SuperAGI should prioritize remediation to prevent exploitation of this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the authenticated user's organization. A remote authenticated attacker from one organization can create or start execution records for agents owned by another organization through /agentexecutions/add or /agentexecutions/add_run.