0.7.0
1 years ago
19 days ago
Known vulnerabilities in the dbgpt package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
dbgpt is a DB-GPT is an experimental open-source project that uses localized GPT large models to interact with your data and environment. With this solution, you can beassured that there is no risk of data leakage, and your data is 100% private and secure. Affected versions of this package are vulnerable to Directory Traversal through the API endpoint How to fix Directory Traversal? There is no fixed version for | [0,) |
dbgpt is a DB-GPT is an experimental open-source project that uses localized GPT large models to interact with your data and environment. With this solution, you can beassured that there is no risk of data leakage, and your data is 100% private and secure. Affected versions of this package are vulnerable to Directory Traversal through the How to fix Directory Traversal? There is no fixed version for | [0,) |
dbgpt is a DB-GPT is an experimental open-source project that uses localized GPT large models to interact with your data and environment. With this solution, you can beassured that there is no risk of data leakage, and your data is 100% private and secure. Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) due to the overly permissive configuration of How to fix Cross-site Request Forgery (CSRF)? There is no fixed version for | [0,) |
dbgpt is a DB-GPT is an experimental open-source project that uses localized GPT large models to interact with your data and environment. With this solution, you can beassured that there is no risk of data leakage, and your data is 100% private and secure. Affected versions of this package are vulnerable to External Control of File Name or Path through the web API How to fix External Control of File Name or Path? There is no fixed version for | [0,) |
dbgpt is a DB-GPT is an experimental open-source project that uses localized GPT large models to interact with your data and environment. With this solution, you can beassured that there is no risk of data leakage, and your data is 100% private and secure. Affected versions of this package are vulnerable to Denial of Service (DoS) through the multipart request boundary processing mechanism. An attacker can cause excessive resource consumption by appending excessive characters to the end of multipart boundaries. How to fix Denial of Service (DoS)? There is no fixed version for | [0,) |