CVE-2025-51475

MEDIUM

TransformerOptimus SuperAGI <0.0.14 - Path Traversal

Title source: llm
STIX 2.1

Description

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().

References (3)

Core 3

Scores

CVSS v3 5.0
EPSS 0.0075
EPSS Percentile 50.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
superagi/superagi 0.0.14
Published Jul 22, 2025
Tracked Since Feb 18, 2026