top of page
perceptive_background_267k.jpg

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/…

Published:

1 March 2026 at 23:00:00

Alert date:

2 March 2026 at 06:01:36

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

A critical code injection vulnerability has been discovered in eosphoros-ai db-gpt version 0.7.5. The flaw affects the Flow Import Endpoint component, specifically the importlib.machinery.SourceFileLoader.exec_module function in the /api/v1/serve/awel/flow/import file. Attackers can exploit this vulnerability remotely through file manipulation to achieve code injection. The exploit has been publicly released and is available for active attacks. The vendor was contacted about the disclosure but has not responded.

Technical details

Mitigation steps:

Affected products:

eosphoros-ai db-gpt

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page