CVE-2025-51472

Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, which are evaluated using eval() without validation during template loading or updates.
Configurations

Configuration 1 (hide)

cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*

History

09 Oct 2025, 16:09

Type Values Removed Values Added
First Time Superagi superagi
Superagi
References () https://github.com/TransformerOptimus/SuperAGI - () https://github.com/TransformerOptimus/SuperAGI - Product
References () https://github.com/TransformerOptimus/SuperAGI/pull/1461 - () https://github.com/TransformerOptimus/SuperAGI/pull/1461 - Exploit, Issue Tracking
References () https://www.gecko.security/blog/cve-2025-51472 - () https://www.gecko.security/blog/cve-2025-51472 - Exploit, Third Party Advisory
CPE cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*

25 Jul 2025, 15:29

Type Values Removed Values Added
Summary
  • (es) La inyección de código en AgentTemplate.eval_agent_config en TransformerOptimus SuperAGI 0.0.14 permite a atacantes remotos ejecutar código Python arbitrario a través de valores maliciosos en configuraciones de plantillas de agente, como el objetivo, las restricciones o el campo de instrucción, que se evalúan utilizando eval() sin validación durante la carga o actualización de la plantilla.

22 Jul 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-77

22 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-22 20:15

Updated : 2025-10-09 16:09


NVD link : CVE-2025-51472

Mitre link : CVE-2025-51472

CVE.ORG link : CVE-2025-51472


JSON object : View

Products Affected

superagi

  • superagi
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')