CVE-2025-51459 | eosphoros-ai db-gpt 0.7.0 ZIP File upload agent.hub.controller.refresh_plugins unrestricted upload
A vulnerability identified as critical has been detected in eosphoros-ai db-gpt 0.7.0. The impacted element is the function agent.hub.controller.refresh_plugins of the file /v1/personal/agent/upload of the component ZIP File Handler. The manipulation leads to unrestricted upload.
This vulnerability is documented as CVE-2025-51459. The attack can be initiated remotely. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.