CVE-2025-0452
eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\' character, which is commonly used as a separator in Windows paths. This vulnerability allows attackers to delete any files on the host system by manipulating the 'plugin_repo_name' variable.
- Affected products
- Db-Gpt
- Dbgpt Db-gpt
- = 0.6.1
- CVSS 3.0
- 8.2 HIGH
- EPSS
- 0.5% (41th percentile)
- Weakness
- CWE-73
- NVD status
- Analyzed
- Published
- 2025-03-20
CVE-2025-0452 at NVD
No indexed exploits for CVE-2025-0452 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-0452 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.