Skip to content
CVE-2025-51475: SuperAGI AFO in File Upload Endpoint

CVE-2025-51475: SuperAGI AFO in File Upload Endpoint

Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.Artemiy Malyshau· Co-founder & CTO2 min read

Key takeaways

  • An AFO was found in SuperAGI’s file upload functionality due to insufficient sanitization of user-supplied filenames.
  • To verify this vulnerability, we need to

Description#

An AFO was found in SuperAGI’s file upload functionality due to insufficient sanitization of user-supplied filenames. The implementation checks file extensions, but it fails to neutralize directory traversal sequences such as ../, allowing attackers to write files outside the intended directory.

The vulnerability lies in the /api/resources/add/<agent_id> endpoint in the superagi/controllers/resources.py file. The file path is constructed using os.path.join() with a base directory and user-provided filename, without enforcing path constraints. Although extensions are validated, an attacker can append a valid extension (e.g., .pdf) to a malicious filename like ../../../etc/passwd%00.pdf to bypass checks.

The file is written using Python’s open() in binary write mode (‘wb’), which allows overwriting existing files. The base directory is retrieved from ResourceHelper.get_root_input_dir, which does not enforce path containment, making arbitrary overwrite possible anywhere within the app’s writeable file system.

Source - Sink Analysis#

  1. Source: upload() in superagi/controllers/resources.py
    • Receives file and filename input directly from user upload
  2. Intermediate: get_root_input_dir() in superagi/helper/resource_helper.py
    • Resolves the base storage directory without normalization or validation
  3. Sink: open() in superagi/controllers/resources.py
    • Writes the file using unsanitized path, allowing path traversal

Proof of Concept#

To verify this vulnerability, we need to

  1. Create a local file and ensure that it has one of the valid extensions
  2. Create a new “resource” with the local file as a parameter
<code class="hljs language-bash"><span class="hljs-comment"># create a malicious file</span>
<span class="hljs-built_in">touch</span> anyfile.txt
<span class="hljs-built_in">echo</span> <span class="hljs-string">"This is a test file"</span> > anyfile.txt

<span class="hljs-comment"># create the resource with said file as a parameter</span>
curl -X POST <span class="hljs-string">"http://127.0.0.1:3000/api/resources/add/1"</span> \
  -H <span class="hljs-string">"Content-Type: multipart/form-data"</span> \
  -F <span class="hljs-string">"file=@anyfile.txt"</span> \
  -F <span class="hljs-string">"name=../../../../etc/passwd.txt"</span> \
  -F <span class="hljs-string">"type=text/plain"</span> \
  -F <span class="hljs-string">"size=1024"</span>
</code>

Output#

<code class="hljs language-bash">{
  <span class="hljs-string">"name"</span>: <span class="hljs-string">"../../../../etc/passwd.txt"</span>,
  <span class="hljs-string">"path"</span>: <span class="hljs-string">"/app/workspace/input/test_1/anyfile.txt"</span>,
  ...
}
</code>

Impact#

This vulnerability allows attackers to:

  • Overwrite arbitrary files on the filesystem
  • Bypass application logic and controls
  • Escalate privileges or disrupt service if critical files are overwritten
Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.

Artemiy Malyshau

Co-founder & CTO

Artemiy served in an elite unit of the Austrian Cyber Forces, defending national infrastructure He was then the first employee at a government-backed cybersecurity research group, where he led security projects for Interpol and national governments. At Gecko he builds the platform trusted to sit inside Fortune 500 codebases, and holds it to the standard those governments taught him.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.

Subscribe to the Gecko Security newsletter

Occasional updates, new content, and insights. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.