


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/…
Published:
1 maart 2026 om 23:00:00
Alert date:
2 maart 2026 om 06:01:36
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A critical code injection vulnerability has been discovered in eosphoros-ai db-gpt version 0.7.5. The flaw affects the Flow Import Endpoint component, specifically the importlib.machinery.SourceFileLoader.exec_module function in the /api/v1/serve/awel/flow/import file. Attackers can exploit this vulnerability remotely through file manipulation to achieve code injection. The exploit has been publicly released and is available for active attacks. The vendor was contacted about the disclosure but has not responded.
Technical details
Mitigation steps:
Affected products:
eosphoros-ai db-gpt
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3409
https://gist.github.com/YLChen-007/d2799d8b2077e50658f12a45bcae9b70
https://vuldb.com/?ctiid.348304
https://vuldb.com/?id.348304
https://vuldb.com/?submit.763745
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
