First published: Thu Mar 20 2025(Updated: )
eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, which is commonly used as a separator in Windows paths. This vulnerability allows attackers to delete any files on the host system by manipulating the 'plugin_repo_name' variable.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
eosphoros-ai db-gpt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0452 is considered a high severity vulnerability due to the potential for arbitrary file deletion on Windows systems.
To fix CVE-2025-0452, ensure that your application properly filters out the '\' character to prevent path traversal issues.
CVE-2025-0452 affects users of the latest version of the eosphoros-ai/DB-GPT application on Windows systems.
The exploitation of CVE-2025-0452 could lead to unauthorized deletion of important files on affected systems.
More information about CVE-2025-0452 can be found in security advisories and vulnerability databases.