Metrics
Affected Vendors & Products
Mon, 02 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eosphoros-ai
Eosphoros-ai db-gpt |
|
| Vendors & Products |
Eosphoros-ai
Eosphoros-ai db-gpt |
Mon, 02 Mar 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/serve/awel/flow/import of the component Flow Import Endpoint. Performing a manipulation as part of File results in code injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | eosphoros-ai db-gpt Flow Import Endpoint import importlib.machinery.SourceFileLoader.exec_module code injection | |
| Weaknesses | CWE-74 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-03-02T04:02:08.022Z
Updated: 2026-03-02T15:05:26.398Z
Reserved: 2026-03-01T09:39:44.943Z
Link: CVE-2026-3409
Updated: 2026-03-02T15:04:57.338Z
Status : Awaiting Analysis
Published: 2026-03-02T05:16:17.450
Modified: 2026-03-02T20:30:10.923
Link: CVE-2026-3409
No data.