CVE-2024-10901: Dbgpt DB-Gpt
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write, enabling them to write arbitrary files to the victim's file system. This can potentially lead to Remote Code Execution (RCE) by writing malicious files such as `__init__.py` in the Python's `/site-packages/` directory.
Affected products
- Dbgpt DB-Gpt: version 0.6.0 only
Published 2025-03-20. Last modified 2026-06-17.