Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7h3r-f4vp-3r8f

Опубликовано: 22 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().

EPSS

Процентиль: 17%
0.00054
Низкий

5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5
nvd
7 месяцев назад

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().

EPSS

Процентиль: 17%
0.00054
Низкий

5 Medium

CVSS3

Дефекты

CWE-22