All 4 CVE vulnerabilities found in db-gpt, with AI-generated Chinese analysis, references, and POCs.
Vendor: eosphoros-ai
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-4505 | eosphoros-ai DB-GPT FastAPI Endpoint controller.py module_plugin.refresh_plugins unrestricted upload CWE-434 | 6.3 | Medium | 2026-03-20 |
| CVE-2026-4504 | eosphoros-ai db-gpt Incomplete Fix editor sql injection CWE-89 | 7.3 | High | 2026-03-20 |
| CVE-2026-3409 | eosphoros-ai db-gpt Flow Import Endpoint import importlib.machinery.SourceFileLoader.exec_module code injection CWE-94 | 7.3 | High | 2026-03-02 |
| CVE-2025-6772 | eosphoros-ai db-gpt import import_flow path traversal CWE-22 | 7.3 | High | 2025-06-27 |
All 4 known CVE vulnerabilities affecting db-gpt with full Chinese analysis, references, and POCs where available.