top of page
perceptive_background_267k.jpg

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/…

Published:

1 maart 2026 om 23:00:00

Alert date:

2 maart 2026 om 06:01:36

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

A critical code injection vulnerability has been discovered in eosphoros-ai db-gpt version 0.7.5. The flaw affects the Flow Import Endpoint component, specifically the importlib.machinery.SourceFileLoader.exec_module function in the /api/v1/serve/awel/flow/import file. Attackers can exploit this vulnerability remotely through file manipulation to achieve code injection. The exploit has been publicly released and is available for active attacks. The vendor was contacted about the disclosure but has not responded.

Technical details

Mitigation steps:

Affected products:

eosphoros-ai db-gpt

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page