CVE-2024-10902
Arbitrary File Upload with Path Traversal in eosphoros-ai/db-gpt
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 9.1EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
20 mar 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file system at any location. The impact of this vulnerability includes the potential for remote code execution (RCE) by writing malicious files, such as a malicious `__init__.py` in the Python's `/site-packages/` directory.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Produtos afetados
eosphoros-ai · eosphoros-ai/db-gptQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →