CVE-2026-51864: DB-GPT DB-GPT vulnerability
Published Sep 30, 2026
·Updated
DB-GPT v0.7.5 and v0.8.0 contains directory traversal in pythonfileupload (packages/dbgpt-app/src/dbgptapp/openapi/apiv1/pythonuploadapi.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Affected Software
1 affected component
DB-GPT DB-GPT=0.7.5, =0.8.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
Description