peter bassill · operator
$ cve CVE-2025-0868 JSON

CVE-2025-0868 EXPLOIT

?
unscored · CVSS · EPSS 17.1% (pctl 97)

Patch early

A public exploit exists.

Description

A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from 0.8.1 through 0.12.0.

Scoring

CVSSunscored
EPSS17.09% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-95
On CISA KEVno
Public exploityes
Published2025-02-20
Last modified2026-06-17

Public exploits

SourceTitleDate
exploit-dbDocsGPT 0.12.0 - Remote Code Execution2025-04-09

References

→ the Explorer  ·  watch your stack  ·  NVD