CVE-2024-10267
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an email that is already in use. The server returns all information associated with the existing account. The vulnerable endpoint is located in the user registration functionality.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.60%
- CWE
- CWE-359
- Published
- 2025-03-20
- Last modified
- 2026-03-13
Affected products
- transformeroptimus transformeroptimus/superagi
Weakness type
Related vulnerabilities
- CVE-2026-88875 — AVideo Incomplete API Sanitization Information Disclosure
- CVE-2026-73008 — Windows Biometric Service Information Disclosure Vulnerability
- CVE-2026-69351 — Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability
- CVE-2026-21827 — HCL Connections is vulnerable to an information disclosure vulnerability
- CVE-2026-53497 — CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)
- CVE-2026-58510 — GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2026-48048 — XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
- CVE-2026-24078 — Exposure of Private Personal Information to an Unauthorized Actor in Data Modem