CVE-2025-51459 | eosphoros-ai db-gpt 0.7.0 ZIP File upload agent.hub.controller.refresh_plugins unrestricted upload
A vulnerability was found in eosphoros-ai db-gpt 0.7.0. It has been classified as critical. Affected is the function agent.hub.controller.refresh_plugins of the file /v1/personal/agent/upload of the component ZIP File Handler. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2025-51459. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.