Medium severity6.5NVD Advisory· Published Jul 22, 2025· Updated Jun 17, 2026
CVE-2025-51472
CVE-2025-51472
Description
Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python code via malicious values in agent template configurations such as the goal, constraints, or instruction field, which are evaluated using eval() without validation during template loading or updates.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=0.0.14
Patches
Vulnerability mechanics
References
2- github.com/TransformerOptimus/SuperAGI/pull/1461nvdExploitIssue Tracking
- www.gecko.security/blog/cve-2025-51472nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.