db-gptGHSA-qccg-9m4q-xfm6
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
Critical9.1CVE-2024-10835 · Published Mar 20, 2025 · updated Jun 29, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| dbgpt PyPI | < 0.7.1 | 0.7.1 |
Details and references
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write using DuckDB SQL, enabling them to write arbitrary files to the victim's file system. This can potentially lead to Remote Code Execution (RCE).
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-89
- Also known as
- CVE-2024-10835, PYSEC-2026-325
More db-gpt advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | DB-GPT vulnerable to Cross-Site Request Forgery CVE-2024-10906High7.1no fix yet | High7.1 | No fix yet |
| Mar 202025 | DB-GPT vulnerable to Arbitrary File Upload with Path Traversal CVE-2024-10902Critical9.1no fix yet | Critical9.1 | No fix yet |
| Mar 202025 | DB-GPT Uncontrolled Resource Consumption vulnerability CVE-2024-10829High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | DB-GPT Arbitrary File Write vulnerability CVE-2024-10901Critical9.1no fix yet | Critical9.1 | No fix yet |
| Mar 202025 | DB-GPT Path Traversal vulnerability CVE-2024-10830High8.2no fix yet | High8.2 | No fix yet |
| Mar 202025 | DB-GPT Absolute Path Traversal vulnerability CVE-2024-10831Critical9.1no fix yet | Critical9.1 | No fix yet |