Dbgpt

Db-gpt

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Veröffentlicht 22.07.2025 00:00:00
  • Zuletzt bearbeitet 11.09.2025 16:13:25

File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plug...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 22.07.2025 00:00:00
  • Zuletzt bearbeitet 11.09.2025 16:09:07

SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with api_editor_v1...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 27.06.2025 18:31:05
  • Zuletzt bearbeitet 15.09.2025 13:53:08

A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /api/v2/serve/awel/flow/import. The manipulation of the argument File leads to path traversal. It is po...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 20.03.2025 10:11:19
  • Zuletzt bearbeitet 17.07.2025 13:37:54

A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability allows an attacker to delete any file on the server by manipulating the `file_key` parameter. The `file_...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 20.03.2025 10:11:01
  • Zuletzt bearbeitet 17.07.2025 13:39:05

eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file write. The issue arises from the ability to pass an absolute path to a call to `os.path.join`, enabling an attacker to write files...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 20.03.2025 10:10:15
  • Zuletzt bearbeitet 15.10.2025 13:15:37

eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 20.03.2025 10:10:05
  • Zuletzt bearbeitet 17.07.2025 13:43:47

In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Origin` to `*` for all requests. This configuration makes all endpoints e...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 20.03.2025 10:09:50
  • Zuletzt bearbeitet 15.10.2025 13:15:37

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters app...

Exploit
  • EPSS 1.06%
  • Veröffentlicht 20.03.2025 10:09:40
  • Zuletzt bearbeitet 17.07.2025 13:40:42

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write, enabling them t...

Exploit
  • EPSS 1.09%
  • Veröffentlicht 20.03.2025 10:09:31
  • Zuletzt bearbeitet 17.07.2025 13:39:16

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write using DuckDB SQL, ...