Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Db Gpt MEDIUM 6.5
CVE-2025-51458

SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted inp…

Patch available
Fix from $1,600 2025-07-22
Db Gpt MEDIUM 6.5
CVE-2025-51459

File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via …

Patch available
Fix from $1,600 2025-07-22
Db Gpt HIGH 7.5
CVE-2025-6772

A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /a…

Fix: after 0.7.2
Fix from $1,950 2025-06-27
Db Gpt HIGH 8.2
CVE-2025-0452

eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The applicati…

No fix yet
Fix from $1,950 2025-03-20
Db Gpt CRITICAL 9.8
CVE-2024-10902

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This …

No fix yet
Fix from $2,300 2025-03-20
Db Gpt HIGH 8.1
CVE-2024-10906

In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which set…

No fix yet
Fix from $1,950 2025-03-20
Db Gpt CRITICAL 9.8
CVE-2024-10835

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control…

No fix yet
Fix from $2,300 2025-03-20
Db Gpt CRITICAL 9.8
CVE-2024-10901

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access contr…

No fix yet
Fix from $2,300 2025-03-20
Db Gpt CRITICAL 9.1
CVE-2024-10831

In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacke…

No fix yet
Fix from $2,300 2025-03-20
Db Gpt CRITICAL 9.1
CVE-2024-10833

eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge'…

No fix yet
Fix from $2,300 2025-03-20
Db Gpt CRITICAL 9.1
CVE-2024-10834

eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file write. The issue arises from …

No fix yet
Fix from $2,300 2025-03-20
Db Gpt HIGH 8.2
CVE-2024-10830

A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability all…

No fix yet
Fix from $1,950 2025-03-20
Db Gpt HIGH 7.5
CVE-2024-10829

A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated a…

No fix yet
Fix from $1,950 2025-03-20