← back
CVE-2025-0868criticalobserved exploitationCWE-95

Remote Code Execution in DocsGPT

90Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.3epss 17%
from disclosure to weapon48 days
Published on NVDFeb 20
1st PoC+48d
VulnCheck+108d
exploitation probability
17%top 3% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from 0.8.1 through 0.12.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Arc53 · DocsGPT
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.