Uploads a crafted ZIP to the unauthenticated flow import endpoint, proving that DB-GPT executes arbitrary Python code from uploaded modules without validation.
Is your app exploitable through CVE-2026-3409?