{"id":"CVE-2026-73034","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-73034","summary":"DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal…","details":"DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipart upload request with a traversal-poisoned user_id header to escape the intended upload directory and write attacker-controlled content to locations such as Python startup hooks, cron directories, or agent scripts, resulting in remote code execution.","published":"2026-08-11T20:18:46.470","modified":"2026-08-11T20:18:46.470","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/eosphoros-ai/DB-GPT/commit/e0c741bd2b5e521b128cffb3f68982dde3f7b359","label":"eosphoros-ai/DB-GPT@e0c741b"},"references":[{"type":"WEB","url":"https://github.com/eosphoros-ai/DB-GPT"},{"type":"WEB","url":"https://github.com/eosphoros-ai/DB-GPT/commit/e0c741bd2b5e521b128cffb3f68982dde3f7b359"},{"type":"WEB","url":"https://github.com/eosphoros-ai/DB-GPT/issues/3104"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/db-gpt-path-traversal-arbitrary-file-write-via-user-id-header"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-11T20:18:46.470"}}