CVE· 2 min read
CVE-2025-51459: DB-GPT RCE in DB-GPT Plugin Upload System
Remote code execution vulnerability in DB-GPT’s plugin upload functionality through unsafe Python code execution.
Artemiy Malyshau
Vulnerability research, CVE write-ups and practical guides from the team building Gecko. Written for the engineers who have to fix the thing, not just triage it.
Remote code execution vulnerability in DB-GPT’s plugin upload functionality through unsafe Python code execution.
Artemiy Malyshau
Stored cross-site scripting vulnerability in Ragflow’s dialog configuration functionality allowing malicious HTML/JavaScript execution.
Artemiy Malyshau
A path traversal vulnerability was found in AIM server. This vulnerability allows remote attackers to write arbitrary files on the server’s filesystem via a malicious tar file extraction.
Artemiy Malyshau
Showing 43 - 45 of 47 articles
Occasional updates and insights. No spam; unsubscribe anytime.