CVE-2025-51472
Last modified
CVE-2025-51472 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, which are evaluated using eval() without validation during template loading or updates.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, which are evaluated using eval() without validation during template loading or updates.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Superagi | Superagi | 0.0.14 |
References
- https://github.com/TransformerOptimus/SuperAGI/pull/1461Exploit, Issue Tracking
- https://www.gecko.security/blog/cve-2025-51472Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-51472?
How severe is CVE-2025-51472?
How do I fix CVE-2025-51472?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-5146A vulnerability has been found in Netcore NBR1005GPEV2, B6V2…6.3
- CVE-2025-51462Stored Cross-site Scripting (XSS) vulnerability in api.apps.…6.1
- CVE-2025-51463Path Traversal in restore_run_backup() in AIM 3.28.0 allows …7
- CVE-2025-51464Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows rem…8.8
- CVE-2025-5147A vulnerability was found in Netcore NBR1005GPEV2, NBR200V2 …6.3
- CVE-2025-51471Cross-Domain Token Exposure in server.auth.getAuthorizationT…6.9
- CVE-2025-51475Arbitrary File Overwrite (AFO) in superagi.controllers.resou…5
- CVE-2025-51479Authorization bypass in update_user_group in onyx-dot-app On…5.4
- CVE-2025-5148A vulnerability was found in FunAudioLLM InspireMusic up to …5.3
- CVE-2025-51480Path Traversal vulnerability in onnx.external_data_helper.sa…8.8
- CVE-2025-51481Local File Inclusion in dagster._grpc.impl.get_notebook_data…6.6
- CVE-2025-51482Remote Code Execution in letta.server.rest_api.routers.v1.to…8.8
Are you affected by CVE-2025-51472?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
