A high-severity vulnerability tracked as CVE-2026-73034 affects eosphoros-ai DB-GPT up to and including version 0.8.1, allowing unauthenticated attackers to exploit the Python file-upload endpoint by placing directory traversal sequences in the user_id HTTP header. The flaw lets remote attackers escape the intended upload directory and write arbitrary files anywhere on the server, creating broad risk to confidentiality, integrity, and availability under the published CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Advisories warn that attackers could place controlled files in sensitive locations such as Python startup hooks, cron directories, or agent scripts, potentially escalating the arbitrary file write into remote code execution. A security patch in the DB-GPT repository hardens the upload logic by restricting user_id to alphanumeric characters, underscores, and hyphens, resolving uploads only under the python_uploads base directory, and enforcing containment checks to block traversal, TOCTOU, and symlink-based escapes; added tests also verify rejection of traversal payloads and unsafe path conditions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE record for the DB-GPT path traversal arbitrary file write states it was newly received by disclosure@vulncheck.com and identifies affected versions up to and including 0.8.1. The entry classifies the issue as CWE-22 and notes that exploitation can lead to arbitrary file write and remote code execution.
VulnCheck published an advisory describing an unauthenticated path traversal flaw in DB-GPT v0.8.1's Python file-upload endpoint. The advisory said attackers could abuse the user_id HTTP header to write arbitrary files on the server and potentially achieve remote code execution.
A DB-GPT commit introduced validation for the user_id header in the Python file upload API, restricting allowed characters and enforcing containment checks so upload paths cannot escape the intended python_uploads directory. The patch also added tests covering traversal attempts, whitespace-padded IDs, default handling, and symlink-based escape scenarios.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.