Impact
TransformerOptimus SuperAGI v0.0.14 contains an improper access control flaw that allows an attacker to delete knowledge entries without providing any authentication and without verifying that the requester owns the organization responsible for the knowledge. This vulnerability could enable a malicious user to remove or corrupt data that is central to the AI model’s performance, potentially causing loss of critical business information or compromising downstream services that rely on the knowledge base.
Affected Systems
The flaw is present in the SuperAGI v0.0.14 source, specifically within superagi/controllers/knowledges.py which handles the POST /knowledges/delete/{knowledge_id} route. Systems running this exact version or earlier source snapshots are vulnerable; later versions that implement proper authentication or ownership verification are not affected.
Risk and Exploitability
The vulnerability requires the attacker to send an HTTP POST request to the delete endpoint. Because no authentication is required, an attacker only needs network access to the host exposing the API. There is no known public exploit, and no EPSS data is available, but the lack of authentication means the risk of exploitation is high if the endpoint is reachable. The vulnerability is not listed in CISA KEV, but its impact remains significant.
OpenCVE Enrichment