Unrated severityNVD Advisory· Published Jul 22, 2025· Updated Jul 22, 2025
CVE-2025-51472
CVE-2025-51472
Description
Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, which are evaluated using eval() without validation during template loading or updates.
Affected products
2- TransformerOptimus/SuperAGIdescription
- Range: =0.0.14
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.