A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to the server, potentially leading to remote code execution or overwriting any file on the server.
CVE ID: CVE-2024-9415
CVSS Base Severity: HIGH
CVSS Base Score: 8.8
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor: transformeroptimus
Product: transformeroptimus/superagi
EPSS Score: 0.28% (probability of being exploited)
EPSS Percentile: 50.85% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)