Medium severity5.0NVD Advisory· Published Jul 22, 2025· Updated Jun 17, 2026
CVE-2025-51475
CVE-2025-51475
Description
Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to overwrite arbitrary files via unsanitised filenames submitted to the file upload endpoint, due to improper handling of directory traversal in os.path.join() and lack of path validation in get_root_input_dir().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=0.0.14
Patches
Vulnerability mechanics
References
2- github.com/TransformerOptimus/SuperAGI/pull/1463nvdExploitIssue Tracking
- www.gecko.security/blog/cve-2025-51475nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.