Impact
TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control flaw in its tool controller where the get_tool and update_tool endpoints accept a caller‑supplied tool_id without verifying that the tool belongs to the caller’s organization. This weakness, identified as CWE‑284, permits an authenticated attacker who is a member of one organization to retrieve or alter the metadata of tools that belong to another organization through the /tools/get/{tool_id} and /tools/update/{tool_id} endpoints.
Affected Systems
The affected system is the TransformerOptimus SuperAGI codebase, version 0.0.14, specifically the controller logic located in superagi/controllers/tool.py. No other vendors or product versions are listed in the current data.
Risk and Exploitability
The risk is substantial for confidentiality and integrity because the vulnerability can be exploited by any authenticated user without additional privileges. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated HTTPS API request to the /tools/get and /tools/update endpoints, requiring knowledge of a valid tool_id provided by a user who holds credentials in their own organization.
OpenCVE Enrichment