VendorsDBGPTdb-gptall versions
Vulnerabilities

DBGPT Db-gpt

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2024-10902
Arbitrary File Upload with Path Traversal in eosphoros-ai/db-gpt
Published 2025-03-20 · Modified
9.8EPSS 0.013
CVE-2024-10835
Arbitrary File Write via SQL Injection in eosphoros-ai/db-gpt
Published 2025-03-20 · Analyzed
9.8EPSS 0.012
CVE-2024-10901
Arbitrary File Write via DuckDB SQL Injection in eosphoros-ai/db-gpt
Published 2025-03-20 · Analyzed
9.8EPSS 0.011
CVE-2024-10831
Arbitrary File Write through Absolute Path Traversal in eosphoros-ai/db-gpt
Published 2025-03-20 · Analyzed
9.1EPSS 0.008
CVE-2024-10833
Arbitrary File Write in eosphoros-ai/db-gpt
Published 2025-03-20 · Modified
9.1EPSS 0.008
CVE-2024-10834
Arbitrary File Write in eosphoros-ai/db-gpt
Published 2025-03-20 · Analyzed
9.1EPSS 0.006
CVE-2024-10830
Path Traversal in eosphoros-ai/db-gpt
Published 2025-03-20 · Analyzed
8.2EPSS 0.007
CVE-2025-0452
Arbitrary File Deletion in eosphoros-ai/DB-GPT
Published 2025-03-20 · Analyzed
8.2EPSS 0.005
CVE-2024-10906
Cross-Site Request Forgery (CSRF) in eosphoros-ai/db-gpt
Published 2025-03-20 · Analyzed
8.1EPSS 0.002
CVE-2024-10829
Denial of Service (DoS) via Multipart Boundary in eosphoros-ai/db-gpt
Published 2025-03-20 · Modified
7.5EPSS 0.007
CVE-2025-6772
eosphoros-ai db-gpt import import_flow path traversal
Published 2025-06-27 · Analyzed
7.5EPSS 0.006
CVE-2025-51459
File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hub._sanitize_filename and plugins_util.scan_plugins.
Published 2025-07-22 · Analyzed
6.5EPSS 0.003
CVE-2025-51458
SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with api_editor_v1.editor_sql_run, editor_chart_run, and datasource.rdbms.base.query_ex.
Published 2025-07-22 · Analyzed
6.5EPSS 0.003