db-gptGHSA-j9g7-mqhh-9hxf
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
Critical9.1CVE-2024-10833 · Published Mar 20, 2025 · updated Jun 29, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| dbgpt PyPI | < 0.6.2 | 0.6.2 |
Details and references
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths.
More db-gpt advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | DB-GPT vulnerable to Cross-Site Request Forgery CVE-2024-10906High7.1no fix yet | High7.1 | No fix yet |
| Mar 202025 | DB-GPT vulnerable to Arbitrary File Upload with Path Traversal CVE-2024-10902Critical9.1no fix yet | Critical9.1 | No fix yet |
| Mar 202025 | DB-GPT Uncontrolled Resource Consumption vulnerability CVE-2024-10829High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | DB-GPT Arbitrary File Write vulnerability CVE-2024-10901Critical9.1no fix yet | Critical9.1 | No fix yet |
| Mar 202025 | DB-GPT Path Traversal vulnerability CVE-2024-10830High8.2no fix yet | High8.2 | No fix yet |
| Mar 202025 | DB-GPT Absolute Path Traversal vulnerability CVE-2024-10831Critical9.1no fix yet | Critical9.1 | No fix yet |