DB-GPT <= 0.8.1 - Arbitrary File Write
CVE-2026-73034
Verified
Description
DB-GPT through 0.8.1 allows unauthenticated arbitrary file writes via a path traversal in the user_id HTTP header of the POST /api/v1/python/file/upload endpoint, letting attackers escape the intended upload directory and write files anywhere, as confirmed by the reflected upload path in the JSON response.
Severity
Critical
CVSS Score
9.8
Exploit Probability
6%
Affected Product
db-gpt
Published Date
August 14, 2026
Template Author
iacker
CVE-2026-73034.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-73034
CWE ID:
cwe-22
Remediation Steps
Upgrade DB-GPT to a version that validates the user_id header and confines the resolved upload path to the python_uploads directory.