{"id":"CVE-2026-51864","title":"DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42)","summary":"DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the i…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-22"],"published":"2026-09-30","updated":"2026-10-01","sourceUpdated":"2026-10-01T19:17:20.977","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-51864","references":[{"url":"https://gist.github.com/Ro1ME/164a2aff1229df650a5bcc2a039900c5","label":"cve@mitre.org"},{"url":"https://github.com/eosphoros-ai/DB-GPT/issues/3027","label":"cve@mitre.org"},{"url":"https://github.com/eosphoros-ai/DB-GPT/issues/3027","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-10-01T18:41:29.891721Z"},"epss":0.00471,"epssPercentile":0.38479,"ingestedAt":"2026-09-30T21:25:07.844Z","slug":"CVE-2026-51864","body":"## Overview\n\nDB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":62,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":214643,"id":"CVE-2026-51864","ts":1790884779229,"field":"exploit_available","old":"false","new":"true"},{"seq":214642,"id":"CVE-2026-51864","ts":1790884779229,"field":"cvss","old":null,"new":"9.1"},{"seq":214641,"id":"CVE-2026-51864","ts":1790884779229,"field":"severity","old":"none","new":"critical"}]}