CVE-2026-4505Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/dbgpt_serve/agent/hub/controller.py of the component FastAPI Endpoint. Such manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-21)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 1Mentions · 2026-03-21: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 103-2003-21
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-212
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-4505 A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/db… https://www.cve.org/CVERecord?id=CVE-2026-4505 ----- Traducción: CVE-2026-4505 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑4505 affecting eosphoros‑ai DB‑GPT up to version 0.7.5, but offers no exploitation, mitigation, or technical depth beyond the affected function.

    0000027
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4505 A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/db… https://www.cve.org/CVERecord?id=CVE-2026-4505

    Post summary

    The post announces a vulnerability (CVE-2026-4505) in eosphoros‑ai DB‑GPT affecting the module_plugin.refresh_plugins function in versions up to 0.7.5, without providing proof of concept, exploit details, or mitigation information.

    00000197
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4505 - eosphoros-ai DB-GPT FastAPI Endpoint http://controller.py module_plugin.refresh_plugins unrestricted upload Intel Report: https://ift.tt/no3Du94

    Post summary

    An alert reports CVE‑2026‑4505, a vulnerability that allows unrestricted file uploads via the eosphoros‑ai DB‑GPT FastAPI endpoint. No PoC, exploit tool, or patch details are mentioned.

    0000065
    334 followersView on X

Explore more