Skip to main content

Vendor/product archive

dbgpt / db-gpt CVEs

Beta · best-effort

13 CVEs tagged to dbgpt / db-gpt6 Critical, 4 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-51458

Published Jul 22, 2025

SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sq…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-51459

Published Jul 22, 2025

File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file up…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6772

Published Jun 27, 2025

A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /api/v2/serve/awel/flow/import.…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0452

Published Mar 20, 2025

eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter th…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-10906

Published Mar 20, 2025

In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Or…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10902

Published Mar 20, 2025

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthori…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10901

Published Mar 20, 2025

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10835

Published Mar 20, 2025

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be ex…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10834

Published Mar 20, 2025

eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file write. The issue arises from the ability to pass an absolut…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10833

Published Mar 20, 2025

eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute pa…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10831

Published Mar 20, 2025

In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10830

Published Mar 20, 2025

A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability allows an attacker to delete any…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10829

Published Mar 20, 2025

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1