LiveActive security incident?Get immediate response
CVE Record

CVE-2026-73034: DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipart upload request with a traversal-poisoned user_id header to escape the intended upload directory and write attacker-controlled content to locations such as Python startup hooks, cron directories, or agent scripts, resulting in remote code execution.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

DB-GPT v0.8.1 can let an unauthenticated remote attacker misuse a file-upload request to place attacker-controlled files outside the intended directory. Writing to code or system-controlled locations could lead to complete server compromise, including data theft, service disruption, and remote code execution.

Executive priority

Treat reachable DB-GPT deployments as an immediate remediation priority. Isolate exposed instances, determine whether v0.8.1 is present, apply the vendor correction, and investigate for unauthorized file writes. Absence from KEV reduces evidence of current campaigns but does not reduce the vulnerability’s severe technical impact.

Technical view

The Python file-upload endpoint trusts the user_id HTTP header when constructing a filesystem path. Directory traversal sequences can escape the upload directory, producing an arbitrary file write. Because exploitation requires no authentication or user interaction and may target executable or automatically loaded files, the supplied CVSS 3.1 score is 9.8.

Likely exposure

DB-GPT v0.8.1 deployments are at risk when untrusted users can reach the affected Python file-upload endpoint. Internet exposure materially increases urgency. The bundle’s structured version entry is ambiguous, so confirm broader affected-version boundaries through vendor guidance rather than assuming only one release is vulnerable.

Exploitation context

The source bundle describes a low-complexity, unauthenticated network attack with potential remote code execution. It does not provide evidence of active exploitation, and the CVE is not identified as being in KEV. Treat it as highly exploitable based on impact and attack prerequisites, not as confirmed in-the-wild activity.

Researcher notes

The core weakness is CWE-22 path traversal in header-derived upload path construction. The patch commit is the strongest supplied remediation reference. Public source metadata is inconsistent about version scope: the title specifies v0.8.1, while the structured affected entry says version “0.” Avoid asserting broader or narrower coverage until the vendor clarifies it.

Mitigation direction

  • Apply the vendor patch commit or an official release containing it after appropriate testing.
  • Restrict untrusted access to the affected file-upload endpoint until remediation is complete.
  • Limit the DB-GPT service account’s filesystem permissions, especially outside its intended upload directory.
  • Follow the GitHub issue and vendor release guidance for confirmed affected and fixed versions.

Validation and detection

  • Inventory DB-GPT deployments and identify instances running v0.8.1 or uncertain versions.
  • Confirm the patch commit is present or verify installation of a vendor-designated fixed release.
  • Safely verify malformed user identifiers cannot cause writes outside the intended upload directory.
  • Review application and proxy logs for suspicious user_id headers associated with multipart uploads.
  • Inspect sensitive writable locations for unexpected or recently modified files.
Prepared
Confidence
high
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-22: File access and web shell behavior lookup

File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
description · low confidence lookup

File access behavior lookup

The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-73034 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
3Timeline events
1ADP providers
5Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9VulnCheck
9.3CVSS 4.0CriticalCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NVulnCheck

Vulnerability scoring details

Base CVSS 4.0 score

9.3Critical
CVSS 4.0 vector shape for CVE-2026-73034Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
eosphoros-aiDB-GPT0affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.