CVE-2026-51914
EUVD-2026-9175902.10.2026, 16:16
TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied agent_id or agent_execution_id values and do not verify that the referenced agent or execution belongs to the authenticated user's organization.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.