PT-2026-104371 · Undefined · Undefined
CVE-2026-51916
·
Publicado
2026-10-02
·
Atualizado
2026-10-02
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete user knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge id.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Undefined