Beveiligingsadvies

CVE-2024-10833

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-03-20 10:10:15
Laatst bijgewerkt 2025-10-15 12:50:11
Toegewezen door @huntr_ai
CVSS-score 9.1
Status PUBLISHED

Beschrijving

eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths.