CVE-2026-51862

Status: Received

Description

DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.

Published
September 30, 2026 9:17 PM
Last Modified
September 30, 2026 9:17 PM
Source
[email protected]

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.