CVE-2025-51458
SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with api_editor_v1.editor_sql_run, editor_chart_run, and datasource.rdbms.base.query_ex.
- Affected products
- Db-Gpt
- Dbgpt Db-gpt
- = 0.7.0
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.3% (25th percentile)
- Weakness
- CWE-89
- NVD status
- Analyzed
- Published
- 2025-07-22
CVE-2025-51458 at NVD
1 known exploit for CVE-2025-51458
Proof-of-concept code and exploit modules indexed by Sploitus