PT-2025-12069 · Unknown · Eosphoros-Ai/Db-Gpt

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-10830

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions eosphoros-ai/db-gpt version 0.6.0
Description A Path Traversal issue exists, allowing an attacker to delete any file on the server by manipulating the file key parameter at the API endpoint "/v1/resource/file/delete". The file key parameter is not properly sanitized, enabling an attacker to specify arbitrary file paths. If the specified file exists, the application will delete it.
Recommendations For version 0.6.0, as a temporary workaround, consider restricting access to the "/v1/resource/file/delete" API endpoint until a patch is available. Additionally, avoid using the file key parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10830
GHSA-8PWP-PHCG-H36G

Affected Products

Eosphoros-Ai/Db-Gpt