CVE-2024-9437

Source
https://cve.org/CVERecord?id=CVE-2024-9437
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9437.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-9437
Published
2025-03-20T10:10:40Z
Modified
2026-08-12T03:51:47Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Unauthenticated Denial of Service in transformeroptimus/superagi
Details

SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in the resource upload request, where appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request causes the server to continuously process each character. This leads to excessive resource consumption and renders the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.

Database specific
{
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-770"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/9xxx/CVE-2024-9437.json"
}
References

Affected packages

Git / github.com/transformeroptimus/superagi

Affected ranges

Type
GIT
Repo
https://github.com/transformeroptimus/superagi
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:superagi:superagi:0.0.14:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0.0.14"
        },
        {
            "last_affected": "0.0.14"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

0.*
0.0.14
v0.*
v0.0.14

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9437.json"