LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-4505

Published
CVSS6.3
Severitymedium
WeaknessCWE-284
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Description

A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/dbgpt_serve/agent/hub/controller.py of the component FastAPI Endpoint. Such manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-4505

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-4505.