CVE-2026-51864

critical

Description

DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.

References

https://github.com/eosphoros-ai/DB-GPT/issues/3027

https://gist.github.com/Ro1ME/164a2aff1229df650a5bcc2a039900c5

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90417

Details

Source: Mitre, NVD

Published: 2026-09-30

Updated: 2026-10-01

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.00471