An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration details, including API keys, of any organization. This could lead to unauthorized access to services and significant data breaches or financial loss.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Superagi
Superagi superagi |
|
CPEs | cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:* | |
Vendors & Products |
Superagi
Superagi superagi |
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration details, including API keys, of any organization. This could lead to unauthorized access to services and significant data breaches or financial loss. | |
Title | Exposure of Sensitive Information in transformeroptimus/superagi | |
Weaknesses | CWE-1230 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:30:29.278Z
Reserved: 2024-10-02T20:27:56.889Z
Link: CVE-2024-9447

Updated: 2025-03-20T17:49:27.173Z

Status : Analyzed
Published: 2025-03-20T10:15:49.200
Modified: 2025-07-29T19:04:30.093
Link: CVE-2024-9447

No data.