CVE-2025-0452
NONE EPSS 39.9%
Published Mar 20, 20251y ago · Modified Jun 17, 20262w ago
Published Mar 20, 2025 1y ago
Last Modified Jun 17, 2026 2w ago
Description
eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, which is commonly used as a separator in Windows paths. This vulnerability allows attackers to delete any files on the host system by manipulating the 'plugin_repo_name' variable.
Threat Intelligence
EPSS Exploit Probability
39.9% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available
Weaknesses 1
CWE-73
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| dbgpt | db-gpt | 0.6.1 | any |
References 1
- huntr.com https://huntr.com/bounties/7e854343-3d61-47d4-ad41-c4d2f356a54a
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.