Unrated severityNVD Advisory· Published Sep 30, 2026
CVE-2026-51864
CVE-2026-51864
Description
DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.