CVE-2024-10835

CVSS 3.0 Score 9.1 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 89

Summary

CVE-2024-10835 is a vulnerability affecting the `db-gpt` web API in version v0.6.0 of eosphoros-ai. The API's `POST /api/v1/editor/sql/run` endpoint allows for the execution of arbitrary SQL queries without proper access control. Malicious actors can exploit this vulnerability to perform Arbitrary File Write using DuckDB SQL, potentially leading to Remote Code Execution (RCE). Attackers can write arbitrary files to the victim's file system, posing a significant security risk. This vulnerability should be addressed promptly to prevent potential data breaches or system compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share