CVE-2025-6280: TransformerOptimus SuperAGI EmailToolKit read_email.py download_attachment path traversal
Published Jun 19, 2025
·Updated
A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function downloadattachment of the file SuperAGI/superagi/helper/reademail.py of the component EmailToolKit. The manipulation of the argument filename leads to path traversal. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
transformeroptimus superagi<0.0.14
TransformerOptimus EmailToolKit
superagi SuperAGI<=0.0.14
Event History
Jun 19, 2025
CVE Published
via MITRE·09:27 PM
Data Sourced
via MITRE·09:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 9, 57515
Event
via FIRST·12:06 PM
Jun 15, 58473
Event
via NVD·04:53 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-6280?
The severity of CVE-2025-6280 is classified as critical.
2
Which software versions are affected by CVE-2025-6280?
CVE-2025-6280 affects TransformerOptimus SuperAGI versions up to 0.0.14.
3
What component is impacted in CVE-2025-6280?
The component impacted by CVE-2025-6280 is EmailToolKit.
4
How do I fix CVE-2025-6280?
To fix CVE-2025-6280, upgrade TransformerOptimus SuperAGI to a version greater than 0.0.14.
5
What specific function is vulnerable in CVE-2025-6280?
The specific function vulnerable in CVE-2025-6280 is download_attachment in read_email.py.