天下漏洞,尽知其名
MEDIUM

CVE-2026-51899 SuperAGI 控制器端点跨组织访问控制漏洞

影响攻击者可越权操作其他组织的智能体

AI 研判

SuperAGI v0.0.14 及更早版本的多个控制器端点存在跨组织访问控制缺陷。这些端点接收 project_id 参数,但未校验该项目是否属于已认证用户所在的组织。

影响范围

SuperAGI

SuperAGI v0.0.14 及更早版本,暂无更详细版本范围公开信息。

漏洞详情

漏洞属于越权访问(访问控制不当)。/api/agents/create、/api/agents/schedule、/api/agents/delete、/api/agents/edit_schedule、/api/agents/stop_schedule 等端点仅要求用户已认证,却未验证 project_id 对应的项目归属组织。因此一个组织的已认证用户可对另一组织项目下的智能体执行创建、调度、编辑、停止和删除操作。

利用条件与风险

利用前提是攻击者拥有 SuperAGI 的合法账号并通过认证,随后构造指向其他组织 project_id 的请求即可越权操作。实战中可导致跨租户数据被篡改或删除,CVSS 4.3 属中危。

修复建议

建议升级至修复该问题的 SuperAGI 版本,并在服务端对 project_id 增加组织归属校验;暂无具体修复版本号公开信息,临时缓解可限制控制器端点访问来源或加强租户隔离审计。

原始情报

In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete agents belonging to a different organization’s project. The endpoints accept a project_id parameter but do not verify that the project belongs to the authenticated user’s organization.