Dbgpt
Dbgpt Db-gpt: vulnerabilidades y CVE
Dbgpt Db-gpt tiene 21 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses8
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-51869 | Sin puntuar | 0.20% | — | 30 sept 2026 | DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host. |
| CVE-2026-51866 | Crítica (9.8) | 0.20% | — | 30 sept 2026 | In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow. |
| CVE-2026-51864 | Crítica (9.1) | 0.47% | — | 30 sept 2026 | DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write… |
| CVE-2026-51862 | Sin puntuar | 0.47% | — | 30 sept 2026 | DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the… |
| CVE-2026-80104 | Crítica (9.3) | 1.1% | — | 25 ago 2026 | DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py… |
| CVE-2026-4505 | Baja (2.1) | 0.35% | — | 20 mar 2026 | A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/dbgpt_serve/agent/hub/controller.py of the component… |
| CVE-2026-4504 | Media (5.5) | 0.41% | — | 20 mar 2026 | A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/editor/ of the component Incomplete Fix. This manipulation causes sql injection. It is possible to… |
| CVE-2026-3409 | Media (5.5) | 0.54% | — | 2 mar 2026 | A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/serve/awel/flow/import of the component Flow Import… |
| CVE-2025-51458 | Media (6.5) | 0.32% | — | 22 jul 2025 | SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints,… |
| CVE-2025-51459 | Media (6.5) | 0.35% | — | 22 jul 2025 | File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload… |
| CVE-2025-6772 | Media (5.5) | 0.64% | — | 27 jun 2025 | A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /api/v2/serve/awel/flow/import. The manipulation of the argument File… |
| CVE-2025-0452 | Alta (8.2) | 0.55% | — | 20 mar 2025 | eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, which is commonly used… |
| CVE-2024-10906 | Alta (8.1) | 0.24% | — | 20 mar 2025 | In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Origin` to `*` for all requests. This… |
| CVE-2024-10902 | Crítica (9.8) | 1.3% | — | 20 mar 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files… |
| CVE-2024-10901 | Crítica (9.8) | 1.1% | — | 20 mar 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform… |
| CVE-2024-10835 | Crítica (9.8) | 1.2% | — | 20 mar 2025 | In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform… |
| CVE-2024-10834 | Crítica (9.1) | 0.62% | — | 20 mar 2025 | eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file write. The issue arises from the ability to pass an absolute path to a call to `os.path.join`,… |
| CVE-2024-10833 | Crítica (9.1) | 0.82% | — | 20 mar 2025 | eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to… |
| CVE-2024-10831 | Crítica (9.1) | 0.82% | — | 20 mar 2025 | In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target… |
| CVE-2024-10830 | Alta (8.2) | 0.72% | — | 20 mar 2025 | A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability allows an attacker to delete any file on the server by manipulating the… |
| CVE-2024-10829 | Alta (7.5) | 0.72% | — | 20 mar 2025 | A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.