In version 0.0.14 of transformeroptimus/superagi, the API endpoint /api/users/get/{id} returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account takeover.
| Software | From | Fixed in |
|---|---|---|
| superagi / superagi | 0.0.14 | 0.0.14.x |