CVE-2024-9431

In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.
References
Link Resource
https://huntr.com/bounties/9b33d7c1-ed0a-4f5b-a378-694570fd990b Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*

History

29 Jul 2025, 19:18

Type Values Removed Values Added
First Time Superagi
Superagi superagi
CPE cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*
References () https://huntr.com/bounties/9b33d7c1-ed0a-4f5b-a378-694570fd990b - () https://huntr.com/bounties/9b33d7c1-ed0a-4f5b-a378-694570fd990b - Exploit, Third Party Advisory
Summary
  • (es) En la versión v0.0.14 de transformeroptimus/superagi, existe una vulnerabilidad de gestión de privilegios incorrecta. Tras iniciar sesión en el sistema, los usuarios pueden cambiar las contraseñas de otros usuarios, lo que podría provocar el robo de cuentas.
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 8.8

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-29 19:18


NVD link : CVE-2024-9431

Mitre link : CVE-2024-9431

CVE.ORG link : CVE-2024-9431


JSON object : View

Products Affected

superagi

  • superagi
CWE
CWE-269

Improper Privilege Management