CVE-2024-9447
CVSS 3.0 Score 6.5 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 1230
Summary
CVE-2024-9447 is an information disclosure vulnerability affecting the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint fails to verify the user's organization, enabling any authenticated user to access sensitive configuration details such as API keys for other organizations. This flaw poses a significant risk, potentially granting unauthorized access to services and resulting in data breaches or substantial financial loss.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.