Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-51475

Опубликовано: 22 июл. 2025
Источник: nvd
CVSS3: 5
EPSS Низкий

Описание

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*

EPSS

Процентиль: 17%
0.00054
Низкий

5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5
github
7 месяцев назад

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().

EPSS

Процентиль: 17%
0.00054
Низкий

5 Medium

CVSS3

Дефекты

CWE-22