← Back

CVE-2024-10833

nvd nist
Published: Mar 20, 2025Modified: Oct 15, 2025

JSON object

Loading...
9.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 3.9 / Impact: 5.2
Source: security@huntr.dev (Secondary)

Description

eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths.

Affected (1)

Products: Dbgpt: Db Gpt
1 product
Db Gpt
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.6.0

References (1)

Source: security@huntr.dev
ExploitThird Party Advisory

Timeline

No history available yet.