Impact
The vulnerability is a path traversal flaw (CWE‑22) located in the Upload routine of transformeroptimus superagi's Multipart Upload Handler. By manipulating the Name argument during a file upload, an attacker can direct the server to write a file outside the intended upload directory. This can expose the system to arbitrary file creation or overwrite of system files, potentially allowing further compromise or persistence.
Affected Systems
TransformerOptimus SuperAGI releases up to 0.0.14 are affected; any remaining releases until the fix is deployed remain at risk.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as moderate severity. The EPSS score is not available, so current exploitation likelihood is unknown, yet the description confirms that a public exploit script exists. The vulnerability can be triggered via the remote Multipart Upload API, meaning any attacker who can reach that endpoint can exploit the flaw even without local privileges.
OpenCVE Enrichment