CVE Vulnerabilities

CVE-2024-9431

Unverified Password Change

Published: Mar 20, 2025 | Modified: Oct 15, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

Name Vendor Start Version End Version
Superagi Superagi 0.0.14 (including) 0.0.14 (including)

Potential Mitigations

References