transformeroptimus/superagi Path Traversal Vulnerability Leading to Remote Code Execution

Vulnerability

A path traversal vulnerability has been identified in the file upload feature of transformeroptimus/superagi, version 0.0.14. This vulnerability allows attackers to upload arbitrary files to the server, which could result in remote code execution or overwriting any file on the server.

Impact

Exploitation of this vulnerability could lead to remote code execution or unauthorized file overwriting on the server.

Reproduction

To reproduce this vulnerability, upload a text file through the Resource Manager's file upload feature. Intercept the request with Burp Suite and modify it to include a path traversal payload that targets the user's SSH authorized_keys file. After sending the modified request, the uploaded content will be written to the authorized_keys file, allowing SSH access to the server without a password.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
10.0
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.5
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.