CVE-2025-0868 EXPLOIT
?
unscored · CVSS · EPSS 17.1% (pctl 97)
Patch early
A public exploit exists.
Description
A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from 0.8.1 through 0.12.0.
Scoring
| CVSS | unscored |
|---|---|
| EPSS | 17.09% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-95 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2025-02-20 |
| Last modified | 2026-06-17 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | DocsGPT 0.12.0 - Remote Code Execution | 2025-04-09 |
References
→ the Explorer · watch your stack · NVD