All 10 CVE vulnerabilities found in eosphoros-ai/db-gpt, with AI-generated Chinese analysis, references, and POCs.
Vendor: eosphoros-ai
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-10830 | Path Traversal in eosphoros-ai/db-gpt CWE-22 | 9.1 | - | 2025-03-20 |
| CVE-2024-10834 | Arbitrary File Write in eosphoros-ai/db-gpt CWE-73 | 9.1 | - | 2025-03-20 |
| CVE-2024-10833 | Arbitrary File Write in eosphoros-ai/db-gpt CWE-36 | 8.8 | - | 2025-03-20 |
| CVE-2024-10906 | Cross-Site Request Forgery (CSRF) in eosphoros-ai/db-gpt CWE-352 | 8.8 | - | 2025-03-20 |
| CVE-2024-10829 | Denial of Service (DoS) via Multipart Boundary in eosphoros-ai/db-gpt CWE-835 | 7.5 | - | 2025-03-20 |
| CVE-2024-10901 | Arbitrary File Write via DuckDB SQL Injection in eosphoros-ai/db-gpt CWE-434 | 9.8 | - | 2025-03-20 |
| CVE-2024-10835 | Arbitrary File Write via SQL Injection in eosphoros-ai/db-gpt CWE-89 | 9.8 | - | 2025-03-20 |
| CVE-2024-10902 | Arbitrary File Upload with Path Traversal in eosphoros-ai/db-gpt CWE-22 | 9.8 | - | 2025-03-20 |
| CVE-2024-10831 | Arbitrary File Write through Absolute Path Traversal in eosphoros-ai/db-gpt CWE-36 | 7.5 | - | 2025-03-20 |
| CVE-2025-0452 | Arbitrary File Deletion in eosphoros-ai/DB-GPT CWE-73 | 9.1 | - | 2025-03-20 |
All 10 known CVE vulnerabilities affecting eosphoros-ai/db-gpt with full Chinese analysis, references, and POCs where available.