CVE-2025-51472

MEDIUM

TransformerOptimus SuperAGI <0.0.14 - Code Injection

Title source: llm
STIX 2.1

Description

Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, which are evaluated using eval() without validation during template loading or updates.

References (3)

Core 3

Scores

CVSS v3 6.5
EPSS 0.0038
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
superagi/superagi 0.0.14
Published Jul 22, 2025
Tracked Since Feb 18, 2026