PT-2025-5828 · Docsgpt · Docsgpt

Eryk Winiarz

·

Published

2025-02-06

·

Updated

2025-10-03

·

CVE-2025-0868

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DocsGPT versions 0.8.1 through 0.12.0
Description A vulnerability has been found in DocsGPT that could result in Remote Code Execution (RCE). Due to improper parsing of JSON data using eval(), an unauthorized attacker could send arbitrary Python code to be executed via the "/api/remote" endpoint.
Recommendations To resolve the issue, update to a version later than 0.12.0. As a temporary workaround, consider disabling the eval() function or restricting access to the "/api/remote" endpoint until a patch is available. Avoid using the eval() function to parse JSON data in the affected API endpoint until the issue is resolved.

Exploit

Fix

RCE

Eval Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14559
CVE-2025-0868
GHSA-9GFF-5V8W-X922

Affected Products

Docsgpt