← voltar
CVE-2025-6772

eosphoros-ai db-gpt import import_flow path traversal

CVSS 6.9 MEDIUMEPSS 0.5%CWE-22
A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /api/v2/serve/awel/flow/import. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
eosphoros-ai · db-gpt

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →