Impact
The vulnerability is a directory traversal flaw in the python_file_upload function of DB‑GPT’s API. A remote attacker can supply a crafted file path that bypasses the intended sandbox and write arbitrary files beyond the application’s workspace. This capability could allow the attacker to place malicious code or configuration files that might be executed by the application or retrieved by other users, compromising confidentiality, integrity, or availability of the system.
Affected Systems
The flaw exists in DB‑GPT version 0.7.5 and 0.8.0, as the code resides in dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py at line 42. Any deployment of these releases that exposes the upload endpoint is susceptible.
Risk and Exploitability
No CVSS score is published for this entry and the EPSS score is not available, so the exact likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog. The attack path is inferred to be through the exposed python_file_upload API endpoint. An attacker would need network access to the API and the ability to craft the file upload request. Given the absence of publicly available exploit code, the risk level should be considered moderate to high for systems that allow remote uploads without additional controls.
OpenCVE Enrichment