CVE-2026-6612: TransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution authorization
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function getagentexecution/updateagentexecution of the file superagi/controllers/agentexecution.py of the component Agent Execution Endpoint. Executing a manipulation of the argument agentexecutionid can lead to authorization bypass. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6612?
The severity of CVE-2026-6612 is considered high due to its potential to allow unauthorized access to agent execution functions.
How do I fix CVE-2026-6612?
To fix CVE-2026-6612, upgrade TransformerOptimus SuperAGI to version 0.0.15 or later, which addresses the authorization vulnerability.
What is affected by CVE-2026-6612?
CVE-2026-6612 affects TransformerOptimus SuperAGI versions up to 0.0.14, specifically the agent_execution.py file.
What are the potential risks of CVE-2026-6612?
The potential risks of CVE-2026-6612 include unauthorized agent execution and manipulation, leading to possible data breaches.
How can I determine if I'm vulnerable to CVE-2026-6612?
You can determine if you're vulnerable to CVE-2026-6612 by checking if you are using TransformerOptimus SuperAGI version 0.0.14 or earlier.