CVE-2025-51475: Path Traversal
Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in getrootinputdir().
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51475?
CVE-2025-51475 is classified as a high-severity vulnerability due to its potential for arbitrary file overwrite.
How do I fix CVE-2025-51475?
To fix CVE-2025-51475, ensure that file upload mechanisms perform proper input validation and sanitize filenames to prevent directory traversal.
Who is affected by CVE-2025-51475?
CVE-2025-51475 impacts users of the SuperAGI TransformerOptimus software version 0.0.14.
What type of attack does CVE-2025-51475 facilitate?
CVE-2025-51475 facilitates arbitrary file overwrite attacks due to improper handling of filenames in file uploads.
Is CVE-2025-51475 exploitable remotely?
Yes, CVE-2025-51475 can be exploited remotely by attackers targeting the file upload endpoint.