A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization | |
| First Time appeared |
Superagi
Superagi superagi |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:superagi:superagi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Superagi
Superagi superagi |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-19T23:45:12.377Z
Reserved: 2026-04-19T05:41:18.481Z
Link: CVE-2026-6586
No data.
Status : Received
Published: 2026-04-20T00:16:34.507
Modified: 2026-04-20T00:16:34.507
Link: CVE-2026-6586
No data.