PT-2025-12071 · Unknown · Eosphoros-Ai/Db-Gpt
Published
2025-03-20
·
Updated
2025-03-20
·
CVE-2024-10833
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
eosphoros-ai/db-gpt version 0.6.0
Description
The issue arises from an arbitrary file write vulnerability through the knowledge API, specifically due to the susceptibility of the file upload endpoint to absolute path traversal. This allows attackers to write files to arbitrary locations on the target server. The
doc file.filename parameter is user-controllable, which enables the construction of absolute paths, leading to this vulnerability.Recommendations
For eosphoros-ai/db-gpt version 0.6.0, consider restricting access to the knowledge API endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the
doc file.filename parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eosphoros-Ai/Db-Gpt