We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-51475



Description

Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().

Reserved 2025-06-16 | Published 2025-07-22 | Updated 2025-07-22 | Assigner mitre

References

github.com/TransformerOptimus/SuperAGI

github.com/TransformerOptimus/SuperAGI/pull/1463

www.gecko.security/blog/cve-2025-51475

cve.org (CVE-2025-51475)

nvd.nist.gov (CVE-2025-51475)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-51475

Support options

Helpdesk Chat, Email, Knowledgebase