Db-gpt
This hub aggregates every CVE we track for Db-gpt, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
AI / MLother
17
CVEs tracked
7
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7CRITICAL7MEDIUM3
Monthly trend
0
0
0
0
0
0
10
0
0
1
2
0
0
0
0
0
0
0
3
0
0
0
0
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Db-gpt.
- CVE-2026-73034DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header9.8
- CVE-2026-4505eosphoros-ai DB-GPT FastAPI Endpoint controller.py module_plugin.refresh_plugins unrestricted upload6.3
- CVE-2026-4504eosphoros-ai db-gpt Incomplete Fix editor sql injection7.3
- CVE-2026-3409eosphoros-ai db-gpt Flow Import Endpoint import importlib.machinery.SourceFileLoader.exec_module code injection7.3
- CVE-2025-51458SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/edito...6.5
- CVE-2025-51459File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/...6.5
- CVE-2025-6772eosphoros-ai db-gpt import import_flow path traversal7.3
- CVE-2024-10830Path Traversal in eosphoros-ai/db-gpt8.2
- CVE-2024-10834Arbitrary File Write in eosphoros-ai/db-gpt9.1
- CVE-2024-10833Arbitrary File Write in eosphoros-ai/db-gpt9.1
- CVE-2024-10906Cross-Site Request Forgery (CSRF) in eosphoros-ai/db-gpt8.1
- CVE-2024-10829Denial of Service (DoS) via Multipart Boundary in eosphoros-ai/db-gpt7.5
- CVE-2024-10901Arbitrary File Write via DuckDB SQL Injection in eosphoros-ai/db-gpt9.8
- CVE-2024-10835Arbitrary File Write via SQL Injection in eosphoros-ai/db-gpt9.8
- CVE-2024-10902Arbitrary File Upload with Path Traversal in eosphoros-ai/db-gpt9.8
Product normalization is registry-driven with AI assist and human review. How it works