← volver
CVE-2025-6772

eosphoros-ai db-gpt import import_flow path traversal

CVSS 6.9 MEDIUMEPSS 0.5%CWE-22
A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /api/v2/serve/awel/flow/import. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
eosphoros-ai · db-gpt

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →