CVE-2026-80104: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in eosphoros-ai DB-GPT
Description
CVE-2026-80104 is a critical path traversal vulnerability in eosphoros-ai's DB-GPT version 0.8.0. The application improperly constructs the destination path for uploaded files without restricting them to the intended upload directory. This allows an unauthenticated remote attacker to write files outside the upload directory, including placing or replacing Python modules within the application package, leading to remote code execution.
CVSS v4.0
Score 9.3critical
Affected software
eosphoros-ai
DB-GPT
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because the DB-GPT skill_upload endpoint uses the multipart filename directly to build the destination path without canonicalizing or validating it against the upload directory. The path construction allows absolute paths or parent directory references (e.g., ../../../tmp/x), enabling files to be written outside the intended directory. Additionally, the endpoint's authentication is flawed: the get_user_from_headers function grants admin role access even without user credentials, making the endpoint accessible to unauthenticated attackers. Consequently, an attacker can write arbitrary files, including malicious Python modules, which the server may later import and execute, resulting in remote code execution.
Potential Impact
An unauthenticated remote attacker can write arbitrary files anywhere the server process has write permissions, including overwriting or adding Python modules in the application package. This can lead to full remote code execution within the server process, compromising the confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the vulnerable endpoint and implement input validation to ensure uploaded filenames cannot escape the designated upload directory. Additionally, fix the authentication logic to properly verify user credentials before granting admin privileges.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-25T19:35:42.640Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8df9edacd9273b49ac7417
Added to database: 08/25/2026, 20:24:13 UTC
Last enriched: 09/09/2026, 21:22:22 UTC
Last updated: 10/08/2026, 18:48:49 UTC
Views: 67
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.