CVE-2025-51459: DB-GPT RCE in DB-GPT Plugin Upload System
Remote code execution vulnerability in DB-GPT’s plugin upload functionality through unsafe Python code execution.
Artemiy Malyshau
Vulnerability research, CVE write-ups and practical guides from the team building Gecko. Written for the engineers who have to fix the thing, not just triage it.
Remote code execution vulnerability in DB-GPT’s plugin upload functionality through unsafe Python code execution.
Artemiy Malyshau
Stored cross-site scripting vulnerability in Ragflow’s dialog configuration functionality allowing malicious HTML/JavaScript execution.
Artemiy Malyshau
A path traversal vulnerability was found in AIM server. This vulnerability allows remote attackers to write arbitrary files on the server’s filesystem via a malicious tar file extraction.
Artemiy Malyshau
Remote code execution vulnerability in SuperAGI through unsafe eval() usage in agent template configuration processing.
Artemiy Malyshau
Arbitrary file overwrite vulnerability in SuperAGI’s file upload functionality due to insufficient path sanitization.
Artemiy Malyshau
Showing 43 - 47 of 47 articles
Occasional updates and insights. No spam; unsubscribe anytime.