CVE-2026-73034: DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the userid HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipart upload request with a traversal-poisoned userid header to escape the intended upload directory and write attacker-controlled content to locations such as Python startup hooks, cron directories, or agent scripts, resulting in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73034?
The severity of CVE-2026-73034 is classified as critical with a score of 9.8.
How do I fix CVE-2026-73034?
To fix CVE-2026-73034, upgrade to the latest version of DB-GPT that addresses this vulnerability.
What type of vulnerability is CVE-2026-73034?
CVE-2026-73034 is a path traversal vulnerability that allows arbitrary file write.
What software is affected by CVE-2026-73034?
CVE-2026-73034 affects the DB-GPT software, specifically version 0.8.1.
Can CVE-2026-73034 be exploited remotely?
Yes, CVE-2026-73034 can be exploited remotely by attackers through crafted HTTP requests.