{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/db-gpt-v0.8.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-73034"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DB-GPT (v0.8.1)"],"_cs_severities":["critical"],"_cs_tags":["web-application-vulnerability","path-traversal","rce"],"_cs_type":"advisory","_cs_vendors":["Eosphoros AI"],"content_html":"\u003cp\u003eDB-GPT version 0.8.1 contains a critical path traversal vulnerability (CVE-2026-73034) that allows unauthenticated remote attackers to write arbitrary files to the underlying server filesystem. The vulnerability exists within the application's file-upload endpoint, which improperly sanitizes the 'user_id' HTTP header. By injecting directory traversal sequences (such as ../) into this header, an attacker can escape the designated upload directory. This flaw is particularly severe as it allows an attacker to overwrite sensitive system files or application configuration, such as Python startup hooks, agent scripts, or task scheduling files, to achieve remote code execution. Given the CVSS score of 9.8, immediate patching or restricting access to the file-upload endpoint is necessary for all deployments of DB-GPT v0.8.1.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target running DB-GPT v0.8.1 with public access to the file-upload endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a multipart HTTP POST request directed at the file-upload endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects path traversal sequences (e.g., ../../../etc/cron.d/malicious) into the 'user_id' HTTP header.\u003c/li\u003e\n\u003cli\u003eThe application processes the header, failing to validate the traversal characters, and resolves the target file path outside the intended upload directory.\u003c/li\u003e\n\u003cli\u003eThe application writes the attacker-supplied payload to the traversal-targeted location on the server filesystem.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the execution of the newly placed file (e.g., waiting for a cron job to run or a service restart).\u003c/li\u003e\n\u003cli\u003eThe server executes the attacker-controlled code, establishing persistence or performing further system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote code execution on the host server. This can lead to total system compromise, data exfiltration, or the deployment of further malicious tools. All organizations running DB-GPT v0.8.1 are affected, and the vulnerability is trivially exploitable by unauthenticated remote actors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade DB-GPT to the latest version immediately to patch CVE-2026-73034.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, implement an ingress-level WAF rule to block HTTP requests containing path traversal sequences (e.g., \u0026quot;../\u0026quot;) within the 'user_id' header.\u003c/li\u003e\n\u003cli\u003eAudit server file integrity to check for unauthorized files written in sensitive system or application directories following this attack vector.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect attempts to exploit the traversal vulnerability in web server logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T21:49:50Z","date_published":"2026-08-11T21:49:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-db-gpt-path-traversal/","summary":"DB-GPT version 0.8.1 is vulnerable to an unauthenticated path traversal attack allowing remote code execution via a crafted user_id HTTP header.","title":"Unauthenticated Path Traversal in DB-GPT","url":"https://feed.craftedsignal.io/briefs/2026-08-db-gpt-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - DB-GPT (V0.8.1)","version":"https://jsonfeed.org/version/1.1"}