Impact
A vulnerability in eosphoros-ai DB-GPT up to version 0.7.5 allows an attacker to upload arbitrary files through the FastAPI endpoint in module_plugin.refresh_plugins. Because the upload content is not validated for type or access control, an attacker could place executable files or scripts on the server and execute them, resulting in remote code execution. This is reflected by the associated CWE identifiers.
Affected Systems
The affected product is eosphoros-ai DB-GPT. Versions up to and including 0.7.5 are vulnerable. No patch information is provided, and the vendor has not yet responded.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The exploit is observable over the network, with no local privilege required. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, but the public disclosure and lack of vendor response mean that attackers could still target exposed instances through the exposed FastAPI endpoint.
OpenCVE Enrichment