CVE-2024-10267

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 359

Summary

CVE-2024-10267 is an information disclosure vulnerability affecting the latest version of transformeroptimus/superagi. Attackers can exploit this vulnerability during the user registration process by attempting to register an account with an email address that is already in use. If successful, the server will return all associated information with the existing account, including sensitive user data such as names, emails, and passwords. The vulnerability lies in the user registration endpoint.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share