Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability has been identified in the tool controller component of TransformerOptimus SuperAGI, a technology used for agentic applications. This issue allows authenticated users from one organization to potentially access or alter tool data belonging to other organizations. The main concern is confirming if this specific technology is in use and, if so, assessing the potential exposure.
- Unauthorized access to organizational tools.
- Matters if agentic applications manage sensitive tool data.
- Confirm usage and assess relevance to business operations.
Attack Path
How an attacker could exploit the issue
An attacker could begin by gaining authenticated access to the application, then using this access to target another organization's tool information. The vulnerability lies in how the tool controller handles requests for tool data, specifically by not checking if the authenticated user belongs to the same organization as the requested tool. This allows unauthorized access to sensitive tool metadata.
- Requires authenticated access.
- Triggered by requesting another organization's tool.
- Risk: unauthorized data access and modification.
Live Threat
Current exploitation, exposure, and threat context
A remote attacker could access or alter tool metadata belonging to other organizations when supported by the advisory. This could occur if an attacker, authenticated within one organization, targets the tool controller's API endpoints with tool IDs from a different organization.
- Tool metadata could be exposed.
- Unauthorized tool access or modification.
- Compromised agent functionality.
Operational Fix
Recommended remediation, mitigation, and detection steps
TransformerOptimus SuperAGI's tool controller contains a critical access control vulnerability, allowing authenticated attackers to access or modify tool metadata across different organizations. This necessitates immediate identification of affected deployments, confirmation of business criticality and network reachability, and accountability assignment before planning remediation.
- Assign ownership to SuperAGI application owners.
- Verify tool controller's network exposure and criticality.
- Plan remediation based on identified risk exposure.