01642 06 11 11 Arrange Call

Arbitrary Code Execution Vulnerability in SuperAGI: Exploiting Unsafe Use of 'eval' Function

CVE-2024-21552 · CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2024-21552

All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.

Learn more about our Cis Benchmark Audit For Server Software.