CVE-2025-51459: Command Injection
File Upload vulnerability in agent.hub.controller.refreshplugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with pluginhub.sanitizefilename and pluginsutil.scanplugins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51459?
CVE-2025-51459 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-51459?
To fix CVE-2025-51459, ensure you update to the latest version of eosphoros-ai DB-GPT that addresses this vulnerability.
What is the impact of CVE-2025-51459?
The impact of CVE-2025-51459 includes unauthorized remote code execution via malicious plugin uploads.
Which versions of eosphoros-ai DB-GPT are affected by CVE-2025-51459?
CVE-2025-51459 affects eosphoros-ai DB-GPT version 0.7.0.
How does CVE-2025-51459 exploit the system?
CVE-2025-51459 exploits the system by allowing attackers to upload malicious ZIP files that execute arbitrary code.