dbgpt
open-source agentic AI data assistant for the next generation of AI + Data products.
Activity
- Latest release
- 2w ago
- Total releases
- 48
- Cadence
- ~7 days
- Last 12 months
- 14
Reach
- Stars
- 19.8k
Details
- License
- MIT
- First release
- Jan 29, 2024
| Version | Released | |
|---|---|---|
0.8.2
patch
| ||
0.8.1
patch
| ||
0.8.0
minor
| ||
0.8.0rc8
pre
| ||
0.8.0rc7
pre
| ||
0.8.0rc6
pre
| ||
0.8.0rc5
pre
| ||
0.8.0rc4
pre
| ||
0.8.0rc3
pre
| ||
0.8.0rc2
pre
| ||
0.8.0rc1
pre
| ||
0.8.0rc0
pre
| ||
0.7.5
patch
| ||
0.7.4
patch
| ||
0.7.3
patch
| ||
0.7.1
patch
| ||
0.7.1rc1
pre
1 CVE
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.1rc0
pre
1 CVE
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.0rc1
pre
1 CVE
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.0rc0
pre
1 CVE
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.3
patch
2 CVEs
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.3rc3
pre
2 CVEs
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.3rc2
pre
2 CVEs
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.3rc1
pre
2 CVEs
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.3rc0
pre
2 CVEs
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.2
patch
2 CVEs
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.1
minor
3 CVEs
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.10
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.9
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.9rc0
pre
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.8
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.7
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.7rc0
pre
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.6
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.6rc0
pre
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.5
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.5rc0
pre
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.4
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.4rc0
pre
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.3
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.3rc0
pre
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.2
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.2rc0
pre
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.1
patch
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.1rc0
pre
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.0
minor
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.4.7
initial
8 CVEs
CVE-2024-10906
PYSEC-2026-1289
GHSA-3248-f932-c76p
Jul 07, 2026
DB-GPT vulnerable to Cross-Site Request Forgery
7.1
/ 10
High
Network
Low
None
Required
Unchanged
None
High
Low
In version 0.6.0 of eosphoros-ai/db-gpt, the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10830
PYSEC-2026-1291
GHSA-8pwp-phcg-h36g
Jul 07, 2026
DB-GPT Path Traversal vulnerability
8.2
/ 10
High
Network
Low
None
None
Unchanged
None
Low
High
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10829
PYSEC-2026-1290
GHSA-6xgj-c5fx-5v57
Jul 07, 2026
DB-GPT Uncontrolled Resource Consumption vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-10835
PYSEC-2026-325
GHSA-qccg-9m4q-xfm6
Jun 29, 2026
DB-GPT is vulnerable to SQL Injection attacks from unauthenticated users
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 20 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
0.7.0
0.7.0rc0
0.7.0rc1
0.7.1rc0
0.7.1rc1
Fixed in
0.7.1
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10833
PYSEC-2026-324
GHSA-j9g7-mqhh-9hxf
Jun 29, 2026
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths. Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 9 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
Fixed in
0.6.2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10902
PYSEC-2026-321
GHSA-3xq5-x4fj-rff7
Jun 29, 2026
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.0, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10901
PYSEC-2026-322
GHSA-7gj6-22m4-qfhx
Jun 29, 2026
DB-GPT Arbitrary File Write vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version v0.6.3 and earlier, the web API Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 15 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
0.6.1
0.6.2
0.6.3
0.6.3rc0
0.6.3rc1
0.6.3rc2
0.6.3rc3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2024-10831
PYSEC-2026-323
GHSA-hhw5-29f6-hf4x
Jun 29, 2026
DB-GPT Absolute Path Traversal vulnerability
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the Affected versions
0.4.7
0.5.0
0.5.1
0.5.10
0.5.1rc0
0.5.2
0.5.2rc0
0.5.3
0.5.3rc0
0.5.4
0.5.4rc0
0.5.5
+ 8 more Show less
0.5.5rc0
0.5.6
0.5.6rc0
0.5.7
0.5.7rc0
0.5.8
0.5.9
0.5.9rc0
References Updated Jul 01, 2026 · Source: OSV.dev |