CyberRota Analysis
AI-GeneratedTransformerOptimus SuperAGI v0.0.14 has a vulnerability in its tool controller that allows remote authenticated attackers to bypass access controls. By exploiting this flaw, an attacker can read or modify tool metadata belonging to other organizations, potentially leading to unauthorized data exposure or manipulation. Organizations using this version of SuperAGI should prioritize addressing this vulnerability to safeguard their tool metadata integrity and confidentiality.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a caller-supplied tool_id and fail to verify organization ownership through the associated toolkit. A remote authenticated attacker from one organization can read or modify another organization's tool metadata through /tools/get/{tool_id} and /tools/update/{tool_id}.