Sploitus

CVE-2025-51459

No indexed exploits for CVE-2025-51459 yet

File Upload vulnerability in agent.hub.controller.refresh_plugins in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary code via a malicious plugin ZIP file uploaded to the /v1/personal/agent/upload endpoint, interacting with plugin_hub._sanitize_filename and plugins_util.scan_plugins.

Affected products
Db-Gpt
Dbgpt Db-gpt
= 0.7.0
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.3% (27th percentile)
Weakness
CWE-77
NVD status
Analyzed
Published
2025-07-22
CVE-2025-51459 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-51459 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-51459 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.