All verified exploits

CVE-2026-3409 Flow Import Code Injection

Deterministic high DB-GPT Added cve-verified-cve-2026-3409

Uploads a crafted ZIP to the unauthenticated flow import endpoint, proving that DB-GPT executes arbitrary Python code from uploaded modules without validation.

Is your app exploitable through CVE-2026-3409?

Scan your domain free