DB-GPT Package Vulnerable to Critical Path Traversal Attack
- Severity
- CRITICAL
- CVSS
- 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Affected component
- db-gpt (pypi)
- Affected versions
- >= v0.8.1, <= v0.8.1 or >= v0.8.0, <= v0.8.0 or >= v0.7.5, <= v0.7.5 or >= v0.7.4, <= v0.7.4 or >= v0.7.3, <= v0.7.3 or >= v0.7.2, <= v0.7.2 or >= v0.7.1, <= v0.7.1 or >= v0.7.0, <= v0.7.0 or >= v0.6.3, <= v0.6.3 or >= v0.6.2, <= v0.6.2 or >= v0.6.1, <= v0.6.1 or >= v0.6.0, <= v0.6.0 or >= v0.5.10, <= v0.5.10 or >= v0.5.9, <= v0.5.9 or >= v0.5.8, <= v0.5.8 or >= v0.5.7, <= v0.5.7 or >= v0.5.6, <= v0.5.6 or >= v0.5.5, <= v0.5.5 or >= v0.5.4, <= v0.5.4 or >= v0.5.3, <= v0.5.3 or >= v0.5.2, <= v0.5.2 or >= v0.5.1, <= v0.5.1 or >= v0.5.0, <= v0.5.0 or >= v0.4.7, <= v0.4.7 or >= v0.4.6, <= v0.4.6 or >= v0.4.5, <= v0.4.5 or >= v0.4.4, <= v0.4.4 or >= v0.4.3, <= v0.4.3 or >= v0.4.2, <= v0.4.2 or >= 0.4.1, <= 0.4.1 or >= v0.4.0, <= v0.4.0 or >= v0.3.9, <= v0.3.9 or >= v0.3.8, <= v0.3.8 or >= v0.3.7, <= v0.3.7 or >= v0.3.6, <= v0.3.6 or >= v0.3.5, <= v0.3.5 or >= v0.3.4, <= v0.3.4 or >= v0.3.3, <= v0.3.3 or >= v0.3.2, <= v0.3.2 or >= v0.3.1, <= v0.3.1 or >= v0.3.0, <= v0.3.0 or >= v0.2.3, <= v0.2.3 or >= v0.2.2, <= v0.2.2 or >= v0.2.1, <= v0.2.1 or >= v0.2.0, <= v0.2.0 or >= v0.1.1, <= v0.1.1 or >= v0.1.0, <= v0.1.0 or >= v0.0.7, <= v0.0.7 or >= v0.0.6, <= v0.0.6 or >= v0.0.5-beta, <= v0.0.5-beta or >= v0.0.4-alpha, <= v0.0.4-alpha or >= v0.0.3, <= v0.0.3 or >= v0.0.2, <= v0.0.2 or >= v0.0.1, <= v0.0.1
- Patched version
- Not yet available
DB-GPT package versions from v0.0.1 to v0.8.1 are reportedly affected by a critical unauthenticated path traversal vulnerability that allows remote code execution.
What happened
DB-GPT package versions from v0.0.1 to v0.8.1 contain an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server. Attackers can send a crafted multipart upload request to escape the intended upload directory and write attacker-controlled content, resulting in remote code execution. This vulnerability is tracked as CVE-2026-73034 with a CVSS score of 9.8.
To assess your exposure, check if your systems are running any version of DB-GPT from v0.0.1 to v0.8.1. If so, you are potentially vulnerable to this critical attack. Review your server filesystems for any unauthorized files as a precautionary measure.
What to do about it
- Upgrade to a fixed version of DB-GPT once it becomes available.
- Review server filesystems for any unauthorized files.
- Monitor the primary sources for updates on a patched version.
- Implement additional security measures to detect and prevent unauthorized file writes.
- Stay informed about the latest security advisories related to DB-GPT.
How 0Day would have caught this
db-gpt is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are potentially affected if you are using any version of DB-GPT from v0.0.1 to v0.8.1.
What should I do right now?
Upgrade to a fixed version of DB-GPT once it becomes available and review your server filesystems for any unauthorized files.
Is there a patched version available?
No official fix has been published yet. Monitor the primary sources for updates.
How severe is this vulnerability?
This vulnerability is rated as CRITICAL with a CVSS score of 9.8.