PT-2025-30448 · Db-Gpt · Db-Gpt

Geckosecurity

·

Published

2025-07-22

·

Updated

2025-10-15

·

CVE-2025-51459

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions DB-GPT version 0.7.0
Description A file upload issue exists in the agent.hub.controller.refresh plugins component of DB-GPT. This allows remote attackers to execute arbitrary code by uploading a malicious plugin ZIP file to the /v1/personal/agent/upload API endpoint. The vulnerability involves interaction with the plugin hub. sanitize filename and plugins util.scan plugins functions.
Recommendations DB-GPT version 0.7.0: As a temporary workaround, consider restricting access to the /v1/personal/agent/upload API endpoint until a patch is available.

Exploit

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-51459

Affected Products

Db-Gpt