CVE-2026-51864: n/a
DB-GPT versions 0.7.5 and 0.8.0 contain a directory traversal vulnerability in the python_file_upload component. This flaw allows a remote attacker to write files outside the intended workspace or storage boundary by exploiting the file upload path validation. No CVSS score is available for this vulnerability.
AI Analysis
Technical Summary
CVE-2026-51864 identifies a directory traversal vulnerability in DB-GPT versions 0.7.5 and 0.8.0 within the python_file_upload functionality (specifically in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py at line 42). The vulnerability allows a remote attacker to write files outside the designated workspace or storage boundary by manipulating the validated file upload path.
Potential Impact
The vulnerability enables unauthorized file writes outside the intended directory, potentially allowing an attacker to place malicious files or overwrite critical files on the system where DB-GPT is running. This could lead to further compromise depending on the environment and file usage, but no specific exploitation details or active exploits are reported.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the vulnerable endpoints and monitor for suspicious file upload activity.
CVE-2026-51864: n/a
Description
DB-GPT versions 0.7.5 and 0.8.0 contain a directory traversal vulnerability in the python_file_upload component. This flaw allows a remote attacker to write files outside the intended workspace or storage boundary by exploiting the file upload path validation. No CVSS score is available for this vulnerability.
Affected software
pkg:github/eosphoros-ai/DB-GPTRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-51864 identifies a directory traversal vulnerability in DB-GPT versions 0.7.5 and 0.8.0 within the python_file_upload functionality (specifically in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py at line 42). The vulnerability allows a remote attacker to write files outside the designated workspace or storage boundary by manipulating the validated file upload path.
Potential Impact
The vulnerability enables unauthorized file writes outside the intended directory, potentially allowing an attacker to place malicious files or overwrite critical files on the system where DB-GPT is running. This could lead to further compromise depending on the environment and file usage, but no specific exploitation details or active exploits are reported.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the vulnerable endpoints and monitor for suspicious file upload activity.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-06-08T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6abd7cc62a4e24523d9c87aa
Added to database: 09/30/2026, 21:19:02 UTC
Last enriched: 09/30/2026, 21:34:02 UTC
Last updated: 10/01/2026, 04:58:32 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.