CVE-2025-51458: SQL Injection
SQL Injection in editorsqlrun and queryex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with apieditorv1.editorsqlrun, editorchartrun, and datasource.rdbms.base.queryex.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51458?
CVE-2025-51458 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-51458?
To fix CVE-2025-51458, update the eosphoros-ai DB-GPT software to the latest version that addresses this SQL injection vulnerability.
What are the exploit vectors for CVE-2025-51458?
CVE-2025-51458 can be exploited through crafted inputs sent to the /v1/editor/sql/run or /v1/editor/chart/run endpoints.
Who is affected by CVE-2025-51458?
CVE-2025-51458 affects users of eosphoros-ai DB-GPT version 0.7.0.
What types of attacks can CVE-2025-51458 enable?
CVE-2025-51458 can enable remote attackers to execute arbitrary SQL statements on the database.