CVE-2026-51864 Details
Description
DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
A directory traversal vulnerability has been identified in DB-GPT versions 0.7.5 and 0.8.0, specifically within the 'python_file_upload' function of the Python upload API. This vulnerability allows remote attackers to write files outside the designated workspace or storage boundaries by exploiting the way file names are handled during the upload process.
Users can update to DB-GPT version 0.8.1, which includes a fix for this vulnerability by constraining the Python upload filenames to prevent directory traversal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Ro1ME/164a2aff1229df650a5bcc2a039900c5 | [email protected] | ExploitTechnical Description |
| https://github.com/eosphoros-ai/DB-GPT/issues/3027 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| DB-GPT | 0.7.5 (semver) 0.8.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion