Impact
An unauthenticated path traversal flaw in DB‑GPT v0.8.1 permits attackers to write arbitrary files by encoding directory traversal sequences into the user_id HTTP header of the file‑upload endpoint. If exploited, the attacker can place malicious content in critical locations such as Python startup hooks, cron directories, or agent scripts. This capability leads directly to remote code execution on the host running the service.
Affected Systems
DB‑GPT from eosphoros‑ai, version 0.8.1. The vulnerability affects any deployment of this version that accepts HTTP multipart uploads without validating the user_id header.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is considered Critical. The EPSS score of 1% indicates that, while the exploit probability is low, it is not negligible. The flaw is unauthenticated and can be triggered over the network, making it a classic remote attack vector. The vulnerability is not currently listed in the CISA KEV catalog, but its high severity warrants immediate attention.
OpenCVE Enrichment