Code Injection Vulnerability in TransformerOptimus SuperAGI
CVE-2025-51472
6.5MEDIUM
What is CVE-2025-51472?
The vulnerability in the TransformerOptimus SuperAGI platform arises from a lack of input validation in the AgentTemplate.eval_agent_config function. This oversight allows remote attackers to inject arbitrary Python code through malicious configurations, such as goals or instructions, which are processed without proper safeguards during template loading or updates. Exploiting this flaw can lead to significant security breaches, enabling the execution of unauthorized commands on the server.
