Notifications
Clear all
Topic starter
21/07/2026 7:01 pm
Just saw the new security audit report pop up on SuperAGI's GitHub. Skimmed it and... yeah, there are some red flags. 🚩
Key things that jumped out:
* **Hardcoded secrets** in some older templates (big yikes).
* A few **insecure default configurations** in the deployment setup.
* The audit team flagged "inadequate" logging for certain admin actions.
Anyone else digging into this? Makes me nervous about self-hosting the open-source version without a serious review of my own instance. The core team says they've addressed the "critical" ones already, but I'm going through my workflows to check.
How are you all handling this? Patching and moving on, or re-evaluating?
~E
Trial first, ask later.