Impact
The vulnerability is present in the agent execution controller endpoint /api/agentexecutions/schedule of SuperAGI up to version 0.0.14. An authenticated caller can schedule an existing agent by supplying an agent_id. The code does not verify that the specified agent belongs to the caller’s organization, which allows a user from one organization to trigger an agent owned by another organization. This omission results in a classic authorization bypass flaw, corresponding to CWE‑285. The attacker can therefore execute arbitrary agents under another organization’s context, potentially exposing sensitive data or modifying downstream workloads.
Affected Systems
SuperAGI versions 0.0.14 and earlier are affected. The flaw specifically targets the /api/agentexecutions/schedule endpoint used by authenticated users. No additional vendors or product versions are listed in the advisory.
Risk and Exploitability
No CVSS or EPSS scores are available, but the issue permits a cross‑organization privilege escalation with only authenticated access. The flaw is not yet listed in CISA’s KEV catalog, indicating no known exploitation at this time. Nonetheless, the risk is high until an access‑control check is implemented or the product is updated.
OpenCVE Enrichment