Unrated severityNVD Advisory· Published Jul 22, 2025· Updated Jul 22, 2025
CVE-2025-51475
CVE-2025-51475
Description
Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().
Affected products
2- TransformerOptimus/SuperAGIdescription
- Range: =0.0.14
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.