CVE-2025-0868criticalobserved exploitationCWE-95

CVE-2025-0868: critical vulnerability in Arc53 DocsGPT

Remote Code Execution in DocsGPT

Published · Updated

90Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.3epss 17%
from disclosure to weapon48 days
Published on NVDFeb 20
1st PoC+48d
VulnCheck+108d
exploitation probability
17%top 3% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from 0.8.1 through 0.12.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Arc53 · DocsGPT
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.