CVE-2025-51459
File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hub._sanitize_filename and plugins_util.scan_plugins.
- Affected products
- Db-Gpt
- Dbgpt Db-gpt
- = 0.7.0
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.3% (27th percentile)
- Weakness
- CWE-77
- NVD status
- Analyzed
- Published
- 2025-07-22
CVE-2025-51459 at NVD
No indexed exploits for CVE-2025-51459 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-51459 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.