Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-51864

CRITICAL · 9.1 CVSS Gepubliceerd: CWE-22

Beschrijving NL

DB-GPT v0.7.5 en v0.8.0 bevat directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). Een externe aanvaller kan het gevalideerde exploitatiepad gebruiken om bestanden buiten de beoogde werkruimte of opslaggrens te schrijven.

Origineel (Engels) tonen

DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.

References