We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with api_editor_v1.editor_sql_run, editor_chart_run, and datasource.rdbms.base.query_ex.
Reserved 2025-06-16 | Published 2025-07-22 | Updated 2025-07-22 | Assigner mitregithub.com/eosphoros-ai/DB-GPT/pull/2650
www.gecko.security/blog/cve-2025-51458
Support options