dbgpt
PyPI8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting dbgptpage 1 of 1
- CVE-2024-10829HIGHCVSS 7.5EG 7.52025-03-20
vulnerable: 0.4.7 ... 0.5.9rc0 (20 versions)
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive cha…
- CVE-2024-10830HIGHCVSS 8.2EG 8.22025-03-20
vulnerable: 0.4.7 ... 0.5.9rc0 (20 versions)
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability allows an attacker to delete any file on the server by manipulating the `file_key` parameter.…
- CVE-2024-10831CRITICALCVSS 9.1EG 9.12025-03-20
vulnerable: 0.4.7 ... 0.5.9rc0 (20 versions)
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises …
- CVE-2024-10833CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.6.22025-03-20
vulnerable: 0.4.7 ... 0.6.1 (21 versions)
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary…
- CVE-2024-10835CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.7.12025-03-20
vulnerable: 0.4.7 ... 0.7.1rc1 (32 versions)
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write using D…
- CVE-2024-10901CRITICALCVSS 9.8EG 9.82025-03-20
vulnerable: 0.4.7 ... 0.6.3rc3 (27 versions)
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write, enab…
- CVE-2024-10902CRITICALCVSS 9.8EG 9.82025-03-20
vulnerable: 0.4.7 ... 0.5.9rc0 (20 versions)
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file…
- CVE-2024-10906HIGHCVSS 8.1EG 8.12025-03-20
vulnerable: 0.4.7 ... 0.5.9rc0 (20 versions)
In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Origin` to `*` for all requests. This configuration makes all …
Check whether dbgpt is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for dbgpt CVEs against the assets you own.
Start Free Scan →