VYPR

Db Gpt

by eosphoros-ai

Source repositories

CVEs (22)

  • CVE-2025-51459MedJul 22, 2025
    risk 0.00cvss 6.5epss 0.00

    File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hub._sanitize_filename and…

  • CVE-2024-10835CriMar 20, 2025
    risk 0.00cvss 9.8epss 0.01

    In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write using DuckDB SQL, enabling them to write…

Page 2 of 2