Arbitrary File Write in Eosphoros AI DB-GPT Affects File Security
CVE-2024-10833
9.1CRITICAL
What is CVE-2024-10833?
A vulnerability in Eosphoros AI's DB-GPT version 0.6.0 allows for arbitrary file writes via its knowledge API. This issue arises from a flaw in the file upload endpoint, which is susceptible to absolute path traversal. By exploiting the 'doc_file.filename' parameter, attackers can manipulate file paths, enabling them to write files to unauthorized locations on the server. This poses significant security risks, potentially compromising the integrity of the system.
Affected Version(s)
eosphoros-ai/db-gpt <= unspecified
