Metrics
Affected Vendors & Products
Mon, 20 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Transformeroptimus
Transformeroptimus superagi |
|
| Vendors & Products |
Transformeroptimus
Transformeroptimus superagi |
Mon, 20 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization | |
| First Time appeared |
Superagi
Superagi superagi |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:superagi:superagi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Superagi
Superagi superagi |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-04-19T23:45:12.377Z
Updated: 2026-04-20T16:33:28.763Z
Reserved: 2026-04-19T05:41:18.481Z
Link: CVE-2026-6586
Updated: 2026-04-20T16:33:23.178Z
Status : Received
Published: 2026-04-20T00:16:34.507
Modified: 2026-04-20T00:16:34.507
Link: CVE-2026-6586
No data.