CVE-2025-0868
DocsGPT Allows Remote Code Execution
EPSS 15.1%
描述
A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint. This issue affects DocsGPT: from 0.8.1 through 0.12.0.
如何修補 CVE-2025-0868
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
- npm/docsgpt—未列出修補版本
CVE-2025-0868 正在被利用嗎?
中等 — EPSS 為 15.1%,可持續追蹤但非最高優先。
受影響套件(1)
- >= 0.8.1, <= 0.12.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |