CVE-2024-21552: Superagi

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.

Affected products

Published 2024-07-22. Last modified 2026-06-17.