PT-2026-103613 · Db-Gpt · Db-Gpt
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
DB-GPT version 0.8.0
Description
A directory traversal issue exists in the
skill upload function within the packages/dbgpt-app/src/dbgpt app/openapi/api v1/agentic data api.py file. This allows a remote attacker to write files outside the intended workspace or storage boundary.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
skill upload function to minimize the risk of exploitation. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Db-Gpt