CVE detail
CVE-2024-10902 — CVE-2024-10902
Published 2025-03-20 · Modified 2026-06-17 · Vendor dbgpt · Product db-gpt · Source nvd
CRITICAL
severity
CVSS-derived band
0.0119
EPSS probability
exploitation probability, 30d
65.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file system at any location. The impact of this vulnerability includes the potential for remote code execution (RCE) by writing malicious files, such as a malicious `__init__.py` in the Python's `/site-packages/` directory.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References