CVE-2024-10902: DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
(updated )
In eosphoros-ai/db-gpt version v0.6.0, the web API POST /v1/personal/agent/upload
is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim’s file system at any location. The impact of this vulnerability includes the potential for remote code execution (RCE) by writing malicious files, such as a malicious __init__.py
in the Python’s /site-packages/
directory.
References
Code Behaviors & Features
Detect and mitigate CVE-2024-10902 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →