eosphoros DB-GPT是eosphoros组织的一个结合数据库与大语言模型的智能开发框架。 eosphoros DB-GPT 0.8.1版本存在路径遍历漏洞,该漏洞源于未经验证的路径遍历,攻击者可通过向Python文件上传端点的user_id HTTP头注入目录遍历序列,将任意文件写入服务器任意位置,导致远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| eosphoros-ai | DB-GPT | ≤ 0.8.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| eosphoros-ai | DB-GPT | 0 ~ 0.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | DB-GPT through 0.8.1 allows unauthenticated arbitrary file writes via a path traversal in the user_id HTTP header of the POST /api/v1/python/file/upload endpoint, letting attackers escape the intended upload directory and write files anywhere, as confirmed by the reflected upload path in the JSON response. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-73034.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet