CVE-2026-51862 Details
Description
DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
A directory traversal vulnerability has been identified in DB-GPT version 0.8.0 within the 'skill_upload' function of the 'agentic_data_api.py' file. This vulnerability allows remote attackers to write files outside the designated workspace or storage boundaries by exploiting the way user-controlled filenames are handled during file uploads.
Users can update to DB-GPT version 0.8.1, which includes a fix for this vulnerability by validating the skill upload filenames to prevent directory traversal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Ro1ME/c09e6aca2e9c7280ca4fabb1f44dcd2a | [email protected] | ExploitTechnical Description |
| https://github.com/eosphoros-ai/DB-GPT/issues/3026 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| DB-GPT | 0.8.0 (semver) 0.8.0rc6 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion