CVE-2024-21552

CRITICAL

SuperAGI - RCE

Title source: llm
STIX 2.1

Description

All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.

Scores

CVSS v3 9.8
EPSS 0.0022
EPSS Percentile 45.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
n/a/SuperAGI
Published Jul 22, 2024
Tracked Since Feb 18, 2026