DB-GPT versions 0.8.0 through before 0.8.1 are affected by CVE-2026-80104, a critical path-traversal and arbitrary-file-write flaw in the skill_upload API. The endpoint incorporates attacker-controlled multipart filenames directly into destination paths, allowing absolute paths or .. sequences to escape the intended upload directory. A separate authentication defect treats requests without a user_id header as administrative, enabling remote unauthenticated attackers to write content wherever the DB-GPT process has permission.
Attackers could overwrite or plant Python modules in writable application paths and gain server-side code execution when those modules are imported. The issue is rated CVSS 9.8 under v3.1 and 9.3 under v4.0. DB-GPT v0.8.1 adds filename validation and other hardening, including restrictions on personal skill-script execution and authentication requirements for knowledge-module endpoints; organizations running earlier releases should upgrade and investigate potentially altered application files.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-80104 was published for a critical flaw affecting DB-GPT 0.8.0 through versions earlier than 0.8.1. The skill-upload endpoint accepted traversal or absolute multipart filenames and, because its authentication handling treated unauthenticated requests as administrative, could let remote attackers write files to server-writable paths and potentially obtain code execution through Python-module imports.
DB-GPT released version 0.8.1, adding validation for skill-upload, Python-upload, and example-file names, restricting personal skill-script execution, and adding authentication to knowledge-module endpoints. The release also hardened configuration-file permissions and introduced product and compatibility updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcepypi.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.