CVE-2025-0452
Arbitrary File Deletion in eosphoros-ai/DB-GPT
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.2EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
20 mar 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, which is commonly used as a separator in Windows paths. This vulnerability allows attackers to delete any files on the host system by manipulating the 'plugin_repo_name' variable.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Productos afectados
eosphoros-ai · eosphoros-ai/db-gpt¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →