vendor:
DocsGPT
by:
Shreyas Malhotra
6.1
CVSS
HIGH
Remote Code Execution
RCE
CWE
Product Name: DocsGPT
Affected Version From: 2000.8.1
Affected Version To: 0.12.0
Patch Exists: NO
Related CWE: CVE-2025-0868
CPE: a:arc53:docsgpt:0.12.0
Platforms Tested: Debian Linux, Ubuntu Linux, Kali Linux
2025
DocsGPT 0.12.0 – Remote Code Execution
The DocsGPT version 0.8.1 through 0.12.0 allows remote attackers to execute arbitrary code via a crafted HTTP request. An attacker can exploit this vulnerability by sending a malicious payload in the 'data' parameter, leading to the execution of arbitrary commands on the target system. This vulnerability has been assigned CVE-2025-0868.
Mitigation:
To mitigate this vulnerability, it is recommended to update DocsGPT to a patched version beyond 0.12.0. Additionally, input validation and sanitization should be enforced to prevent malicious payloads.