Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability in the agent execution controller for SuperAGI allows authenticated users to access or control agents belonging to other organizations. This could potentially lead to unauthorized actions or data exposure if not properly managed.
- Unauthorized access to another organization's agents.
- Matters due to potential for data misuse or disruption.
- Confirm relevance and exposure to your deployed agents.
Attack Path
How an attacker could exploit the issue
An attacker with authenticated access to one organization could manipulate the agent execution controller to create or run agents belonging to a different organization. This is possible because the system fails to properly verify ownership of agent IDs when new execution records are requested. Successful exploitation allows an attacker to impact agent operations in another organization.
- Authenticated access to the system is required.
- Caller-supplied agent IDs are not validated.
- Unauthorized agent execution and control.
Live Threat
Current exploitation, exposure, and threat context
A remote attacker with authentication could abuse improper access control to create or start agent execution records for agents belonging to different organizations. This could affect the integrity and availability of agent execution data within the affected system.
- Agent execution data at risk.
- Unauthorized agent execution creation.
- Compromised agent operational integrity.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts SuperAGI's agent execution controller, allowing authenticated remote attackers to manipulate agents across different organizations. The primary responsibility for addressing this typically falls to the platform or application owners who manage SuperAGI deployments, in coordination with security teams to understand exposure. The first practical step is to identify all SuperAGI instances, determine their reachability and business criticality, and confirm ownership before planning remediation.
- Platform owners must identify all instances.
- Verify agent data access and cross-organization exposure.
- Coordinate remediation with affected application owners.