Metrics
Affected Vendors & Products
Fri, 27 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 27 Jun 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /api/v2/serve/awel/flow/import. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | eosphoros-ai db-gpt import import_flow path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-27T18:31:05.585Z
Updated: 2025-06-27T19:06:42.576Z
Reserved: 2025-06-27T10:17:13.526Z
Link: CVE-2025-6772

Updated: 2025-06-27T19:06:32.282Z

Status : Awaiting Analysis
Published: 2025-06-27T19:15:31.500
Modified: 2025-06-30T18:38:23.493
Link: CVE-2025-6772

No data.