CVE-2026-4504Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/editor/ of the component Incomplete Fix. This manipulation causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-03-21)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-20: 1Mentions · 2026-03-21: 3Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 103-2003-21
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-213
Disclosure2General1
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4504 A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/editor/ of the component Incomplete Fix. This mani… https://www.cve.org/CVERecord?id=CVE-2026-4504 ----- Traducción: CVE-2026-4504 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-4504 is reported as a flaw in eosphoros-ai db-gpt up to version 0.7.5, affecting code in /api/v1/editor/, with no PoC, exploit, patch, or active exploitation information provided.

    0000029
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4504 A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/editor/ of the component Incomplete Fix. This mani… https://www.cve.org/CVERecord?id=CVE-2026-4504

    Post summary

    A vulnerability (CVE-2026-4504) has been identified in eosphoros-ai db-gpt up to 0.7.5 affecting code in the /api/v1/editor/ component, but no specific technical details or exploitation evidence are provided.

    00000203
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4504 - eosphoros-ai - db-gpt - https://www.redpacketsecurity.com/cve-alert-cve-2026-4504-eosphoros-ai-db-gpt/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4504 #eosphoros-ai #db-gpt

    Post summary

    The post functions as a brief CVE alert, referencing CVE‑2026‑4504 and linking to an external resource, but provides no further details on exploitation, mitigation, or technical specifics.

    0000064
    3.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4504 - eosphoros-ai db-gpt Incomplete Fix editor sql injection Intel Report: https://ift.tt/jTxDep8

    Post summary

    An alert notes the existence of CVE-2026-4504, a SQL injection flaw in eosphoros-ai db-gpt's editor, with an incomplete fix and an accompanying Intel Report.

    0000063
    334 followersView on X

Explore more