CVE-2025-6772: eosphoros-ai db-gpt import import_flow path traversal
A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function importflow of the file /api/v2/serve/awel/flow/import. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6772?
CVE-2025-6772 has been classified as critical.
How does CVE-2025-6772 affect eosphoros-ai db-gpt?
CVE-2025-6772 affects the import_flow function in eosphoros-ai db-gpt versions up to 0.7.2, leading to a path traversal vulnerability.
What can attackers achieve with CVE-2025-6772?
Attackers can exploit CVE-2025-6772 to perform remote attacks leveraging path traversal vulnerabilities.
How can I mitigate CVE-2025-6772?
To mitigate CVE-2025-6772, update eosphoros-ai db-gpt to the latest version beyond 0.7.2.
Is CVE-2025-6772 publicly known?
Yes, CVE-2025-6772 is a publicly documented vulnerability.