CVE-2024-9415

Source
https://cve.org/CVERecord?id=CVE-2024-9415
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9415.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-9415
Published
2025-03-20T10:09:06.219Z
Modified
2026-07-15T01:49:01.209323733Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Path Traversal in transformeroptimus/superagi
Details

A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to the server, potentially leading to remote code execution or overwriting any file on the server.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9415.json",
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/transformeroptimus/superagi

Affected ranges

Type
GIT
Repo
https://github.com/transformeroptimus/superagi
Events
Database specific
{
    "cpe": "cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "0.0.14"
        },
        {
            "last_affected": "0.0.14"
        }
    ]
}

Affected versions

0.*
0.0.14
v0.*
v0.0.14

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9415.json"