We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-51458



Description

SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary SQL statements via crafted input passed to the /v1/editor/sql/run or /v1/editor/chart/run endpoints, interacting with api_editor_v1.editor_sql_run, editor_chart_run, and datasource.rdbms.base.query_ex.

Reserved 2025-06-16 | Published 2025-07-22 | Updated 2025-07-22 | Assigner mitre

References

github.com/eosphoros-ai/DB-GPT/pull/2650

www.gecko.security/blog/cve-2025-51458

cve.org (CVE-2025-51458)

nvd.nist.gov (CVE-2025-51458)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-51458

Support options

Helpdesk Chat, Email, Knowledgebase