Product
dbgpt db gpt
13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-51458
CVE-2025-51459
CVE-2025-6772
CVE-2025-0452
CVE-2024-10906
CVE-2024-10902
CVE-2024-10901
CVE-2024-10835
CVE-2024-10834
CVE-2024-10833
CVE-2024-10831
CVE-2024-10830
CVE-2024-10829
all versions
SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL stateme
all versions
File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute
<= 0.7.2
A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_
all versions
eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endp
all versions
In version 0.6.0 of eosphoros-ai/db-gpt, the
uvicorn app created by dbgpt_server uses an overly permissive instance of `CORSMiall versions
In eosphoros-ai/db-gpt version v0.6.0, the web API
POST /v1/personal/agent/upload is vulnerable to Arbitrary File Upload with Paall versions
In eosphoros-ai/db-gpt version v0.6.0, the web API
POST /api/v1/editor/chart/run allows execution of arbitrary SQL queries withoall versions
In eosphoros-ai/db-gpt version v0.6.0, the web API
POST /api/v1/editor/sql/run allows execution of arbitrary SQL queries withoutall versions
eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file write. The
all versions
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading f
all versions
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerabilit
all versions
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint
/v1/resource/file/delete. Thiall versions
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allow