Summary
CVE-2026-80104 is a critical path traversal vulnerability in DB-GPT, an open-source AI-powered data platform developed by eosphoros-ai. The flaw resides in the skill_upload endpoint, which fails to validate uploaded filenames, allowing an unauthenticated remote attacker to write arbitrary files anywhere the server process can access. Because the written files can include Python modules that get imported by the application, the vulnerability can be leveraged to achieve remote code execution.
Technical details
- Root cause: the
skill_uploadfunction takes the client-suppliedfile.filenameas-is and writes the uploaded request body toupload_dir / filenamewithout canonicalizing the path or enforcing directory boundaries. - Trigger condition: submitting a multipart upload with a filename containing traversal sequences (e.g.
../../../tmp/x) or an absolute path (e.g./tmp/x) causes the file to be written outside the intended upload directory. - Attack vector: network, no authentication required — the endpoint is reachable by any remote, unauthenticated client.
- Impact: arbitrary file write on the server filesystem; an attacker can drop or overwrite Python modules inside the application package, resulting in remote code execution when those modules are subsequently imported by the application.
Affected software
- eosphoros-ai DB-GPT (PyPI package
dbgpt-app), version 0.8.0 up to (but not including) 0.8.1. - Fixed in DB-GPT 0.8.1.
Severity
- CVSS v3.1 Base Score: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0 Base Score: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: upgrade DB-GPT to version 0.8.1 or later, where filename validation for the skill upload feature has been fixed.
- If patching is not immediately possible: restrict network access to the
skill_uploadendpoint (and the DB-GPT management interface generally) to trusted internal networks only, disable or block the endpoint at a reverse proxy/WAF, and monitor for uploads containing path traversal sequences (../) or absolute paths in filenames.

