VYPR

DB-GPT

by DB GPT

CVEs (1)

  • CVE-2026-73034CriAug 11, 2026
    risk 0.57cvss 9.8epss

    DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can…