/Vulnerability Library

DB-GPT <= 0.8.1 - Arbitrary File Write

CVE-2026-73034
Verified

Description

DB-GPT through 0.8.1 allows unauthenticated arbitrary file writes via a path traversal in the user_id HTTP header of the POST /api/v1/python/file/upload endpoint, letting attackers escape the intended upload directory and write files anywhere, as confirmed by the reflected upload path in the JSON response.

Severity

Critical

CVSS Score

9.8

Exploit Probability

6%

Affected Product

db-gpt

Published Date

August 14, 2026

Template Author

iacker

CVE-2026-73034.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-73034
CWE ID:
cwe-22

References

https://www.vulncheck.com/advisories/db-gpt-path-traversal-arbitrary-file-write-via-user-id-headerhttps://github.com/eosphoros-ai/DB-GPT/issues/3104https://github.com/eosphoros-ai/DB-GPT/commit/e0c741bd2b5e521b128cffb3f68982dde3f7b359https://nvd.nist.gov/vuln/detail/CVE-2026-73034

Remediation Steps

Upgrade DB-GPT to a version that validates the user_id header and confines the resolved upload path to the python_uploads directory.