Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-51901

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SuperAGI 版本 0.0.14 及以下存在不正确的访问控制漏洞。代理执行控制器端点 允许来自一个组织的已认证用户,在没有进行适当授权检查的情况下,调度属于另一个组织的现有代理。该端点接受 参数,但并未验证该代理是否属于经过身份验证的用户所属的组织。

AI Predicted 8.1 Difficulty: Easy EPSS 0.16% · P4

Possible ATT&CK Techniques 1 AI

T1199 · Trusted Relationship

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51901

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id parameter but does not verify that the agent belongs to the authenticated user's organization.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51901

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51901

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-51901 (1)

Proof of Concept for CVE-2026-51901 (1)

Same Patch Batch · n/a · 2026-10-02 · 14 CVEs total

CVE-2026-51906 TaskingAI v0.3.0 DALL-E 3目录遍历漏洞
CVE-2026-51904 SuperAGI≤v0.0.14越权漏洞
CVE-2026-51907 TaskingAI v0.3.0插件目录遍历漏洞
CVE-2026-51898 pandas-ai 3.0.0 代码执行器存在代码注入漏洞
CVE-2026-51899 SuperAGI <0.0.14 存在水平权限漏洞
CVE-2026-51922 AgentScope v1.0.20 命令注入漏洞
CVE-2026-51916 TransformerOptimus SuperAGI v0.0.14 越权删除漏洞
CVE-2026-51918 FinRobot 1.0.0 CodingUtils.create_file_with_code() 代码注入漏洞
CVE-2026-51911 Vanna v2.0.2代码注入漏洞
CVE-2026-51917 FinRobot v1.0.0 CodingUtils模块代码注入漏洞
CVE-2026-51915 TransformerOptimus SuperAGI v0.0.14工具控制器越权漏洞
CVE-2026-51914 TransformerOptimus SuperAGI v0.0.14 存在错误访问控制漏洞
CVE-2026-67989 Ruby_llm Ruby 3.1.x ReDoS漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-51901

No comments yet


Leave a comment