Junglewise Threat Intelligence

CVE-2026-80104: DB-GPT path traversal in skill upload endpoint

CVE-2026-80104 · Severity: critical · CVSS 9.8 · Published 2026-08-25

Executive brief

DB-GPT is an open-source AI data assistant that allows users to upload custom skills. The skill upload endpoint does not properly validate filenames, allowing remote attackers to write files to arbitrary locations on the server. An attacker can exploit this to write malicious Python code that gets executed when imported by the application, leading to complete server compromise without requiring any authentication.

Technical details

The vulnerability is a path traversal/arbitrary file write flaw in the `skill_upload` endpoint (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py). The endpoint takes the multipart upload filename directly and constructs the destination path using path concatenation without canonicalization or validation. Filenames like `../../../tmp/x` or `/tmp/x` resolve outside the intended upload directory. The vulnerability is made critical by an authentication bypass: the endpoint's auth check (`get_user_from_headers`) grants admin privileges regardless of whether credentials are provided. An unauthenticated attacker can thus write arbitrary files—including malicious Python modules with .py suffixes into the application package—and achieve remote code execution when those modules are imported by the running application.

Affected products

  • eosphoros-ai DB-GPT v0.8.0 and possibly earlier versions

Timeline

  • 2026-08-25: disclosed: CVE-2026-80104 published

References

Related threats