Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-51916

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TransformerOptimus SuperAGI v0.0.14 在 文件的 函数中存在一个不正确的访问控制漏洞。在受影响源码快照中, 请求在路由层面未要求身份认证,且未验证所提供的 是否属于当前用户所属的组织,即可直接删除选定的知识对象。

AI Predicted 9.1 Difficulty: Easy

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51916

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51916

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51916

请登录查看更多情报信息。

Proof of Concept for CVE-2026-51916 (1)

Same Patch Batch · n/a · 2026-10-02 · 14 CVEs total

CVE-2026-51906 TaskingAI v0.3.0 DALL-E 3目录遍历漏洞
CVE-2026-51904 SuperAGI≤v0.0.14越权漏洞
CVE-2026-51907 TaskingAI v0.3.0插件目录遍历漏洞
CVE-2026-51901 SuperAGI <=0.0.14 越权访问漏洞
CVE-2026-51898 pandas-ai 3.0.0 代码执行器存在代码注入漏洞
CVE-2026-51899 SuperAGI <0.0.14 存在水平权限漏洞
CVE-2026-51922 AgentScope v1.0.20 命令注入漏洞
CVE-2026-51918 FinRobot 1.0.0 CodingUtils.create_file_with_code() 代码注入漏洞
CVE-2026-51911 Vanna v2.0.2代码注入漏洞
CVE-2026-51917 FinRobot v1.0.0 CodingUtils模块代码注入漏洞
CVE-2026-51915 TransformerOptimus SuperAGI v0.0.14工具控制器越权漏洞
CVE-2026-51914 TransformerOptimus SuperAGI v0.0.14 存在错误访问控制漏洞
CVE-2026-67989 Ruby_llm Ruby 3.1.x ReDoS漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-51916

No comments yet


Leave a comment