Impact
DB-GPT 0.8.0 contains a directory traversal flaw in the skill_upload endpoint that allows a remote attacker to write files outside the intended workspace or storage boundary. If an attacker can place files in sensitive directories, they could overwrite configuration files or inject malicious payloads, leading to remote code execution or data compromise.
Affected Systems
The vulnerability affects deployments of DB-GPT version 0.8.0. No specific vendor or product list is provided, indicating that any instance of this open‑source tool using the affected version is at risk.
Risk and Exploitability
The flaw is exploitable via a documented path in the source code. While a CVSS score is not available in the public data and EPSS is not offered, the nature of directory traversal suggests high severity. The vulnerability is not listed in CISA’s KEV catalog, but the ability to write arbitrary files poses a significant risk if the application executes or trusts uploaded content. Attackers can use the validated exploitation route unless mitigations such as disabling the upload endpoint or applying the official patch are enforced.
OpenCVE Enrichment