CVE-2024-9431

HIGH

transformeroptimus/superagi <0.0.14 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.

Scores

CVSS v3 8.8
EPSS 0.0010
EPSS Percentile 28.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-620
Status published
Products (1)
superagi/superagi 0.0.14
Published Mar 20, 2025
Tracked Since Feb 18, 2026