Description
DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote File Write with potential for arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

DB-GPT 0.8.0 contains a directory traversal flaw in the skill_upload endpoint that allows a remote attacker to write files outside the intended workspace or storage boundary. If an attacker can place files in sensitive directories, they could overwrite configuration files or inject malicious payloads, leading to remote code execution or data compromise.

Affected Systems

The vulnerability affects deployments of DB-GPT version 0.8.0. No specific vendor or product list is provided, indicating that any instance of this open‑source tool using the affected version is at risk.

Risk and Exploitability

The flaw is exploitable via a documented path in the source code. While a CVSS score is not available in the public data and EPSS is not offered, the nature of directory traversal suggests high severity. The vulnerability is not listed in CISA’s KEV catalog, but the ability to write arbitrary files poses a significant risk if the application executes or trusts uploaded content. Attackers can use the validated exploitation route unless mitigations such as disabling the upload endpoint or applying the official patch are enforced.

Generated by OpenCVE AI on September 30, 2026 at 23:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest upgrade or patch for DB-GPT that eliminates the directory traversal bug.
  • If an immediate upgrade is not feasible, block or remove the skill_upload endpoint using a firewall or WAF to stop the ability to upload files.
  • Add server‑side validation to ensure that any file paths remain confined to the allowed workspace, rejecting any attempts to traverse outside the directory boundary.
  • Monitor system logs for unexpected file creation or modification events around the storage directories.

Generated by OpenCVE AI on September 30, 2026 at 23:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Directory Traversal Allowing Remote File Write in DB-GPT Skill Upload
Weaknesses CWE-22

Wed, 30 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:57:08.681Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51862

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:12.243

Modified: 2026-09-30T21:17:12.243

Link: CVE-2026-51862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:15:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')