CVE-2025-51472

Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, which are evaluated using eval() without validation during template loading or updates.
Configurations

No configuration.

History

25 Jul 2025, 15:29

Type Values Removed Values Added
Summary
  • (es) La inyección de código en AgentTemplate.eval_agent_config en TransformerOptimus SuperAGI 0.0.14 permite a atacantes remotos ejecutar código Python arbitrario a través de valores maliciosos en configuraciones de plantillas de agente, como el objetivo, las restricciones o el campo de instrucción, que se evalúan utilizando eval() sin validación durante la carga o actualización de la plantilla.

22 Jul 2025, 21:15

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

22 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-22 20:15

Updated : 2025-07-25 15:29


NVD link : CVE-2025-51472

Mitre link : CVE-2025-51472

CVE.ORG link : CVE-2025-51472


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')