DB-GPTGHSA-3xq5-x4fj-rff7
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
Critical9.1CVE-2024-10902 · Published Mar 20, 2025 · updated Jun 29, 2026
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file system at any location. The impact of this vulnerability includes the potential for remote code execution (RCE) by writing malicious files, such as a malicious `__init__.py` in the Python's `/site-packages/` directory.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| dbgpt PyPI | <= 0.6.0 | No fix yet |
Details and references
More DB-GPT advisories
All DB-GPT| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | DB-GPT vulnerable to Cross-Site Request Forgery | High7.1 | No fix yet |
| Mar 202025 | DB-GPT Uncontrolled Resource Consumption vulnerability | High7.5 | No fix yet |
| Mar 202025 | DB-GPT Arbitrary File Write vulnerability | Critical9.1 | No fix yet |
| Mar 202025 | DB-GPT Path Traversal vulnerability | High8.2 | No fix yet |
| Mar 202025 | DB-GPT Absolute Path Traversal vulnerability | Critical9.1 | No fix yet |
| Mar 202025 | DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload | Critical9.1 | 0.6.2 |