CVE-2024-9439

Publication date

2025-03-20 10:10:34

Family

@huntr_ai

State

PUBLISHED

Description

SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters, which are then fed to the eval function without any sanitization or checks in place. This vulnerability can lead to full system compromise.