CVE-2024-9431

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 269

Summary

CVE-2024-9431 is a newly disclosed vulnerability affecting transformeroptimus/superagi in version v0.0.14. This issue involves an improper privilege management flaw, which allows logged-in users to alter the passwords of other accounts. Consequently, this vulnerability poses a significant risk for potential account takeover attacks. Unauthorized users could exploit this weakness to gain access to other users' accounts, causing potential data breaches or unauthorized system actions. System administrators are advised to promptly update their installations to the latest, secure version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share