In version 0.0.14 of transformeroptimus/superagi, the API endpoint /api/users/get/{id} returns the users password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account takeover.
The product stores a password in plaintext within resources such as memory or files.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Superagi | Superagi | 0.0.14 (including) | 0.0.14 (including) |