A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/controllers/user.py of the component User Update Endpoint. The manipulation of the argument user_id results in authorization bypass. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sun, 19 Apr 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/controllers/user.py of the component User Update Endpoint. The manipulation of the argument user_id results in authorization bypass. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | TransformerOptimus SuperAGI User Update Endpoint user.py update_user authorization | |
| First Time appeared |
Superagi
Superagi superagi |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:superagi:superagi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Superagi
Superagi superagi |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-04-19T23:15:16.091Z
Updated: 2026-04-19T23:15:16.091Z
Reserved: 2026-04-19T05:41:06.301Z
Link: CVE-2026-6584
No data.
Status : Received
Published: 2026-04-20T00:16:34.093
Modified: 2026-04-20T00:16:34.093
Link: CVE-2026-6584
No data.
ReportizFlow