Transformeroptimus Superagi Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in Transformeroptimus Superagi version 0.0.14. This vulnerability arises because the application does not adequately verify authorization for several API endpoints. As a result, attackers can view, edit, and delete information belonging to other users without proper authorization. The affected endpoints include /get/project/{project_id}, /get/schedule_data/{agent_id}, /delete/{agent_id}, /get/organisation/{organisation_id}, and /get/user/{user_id}.

Impact

Exploitation of this vulnerability allows unauthorized users to access, modify, or delete information belonging to other users, potentially leading to unauthorized data exposure or loss.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
7.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.