CRITICAL 9.8 CVE-2026-80104 Published 25 Aug 2026

DB-GPT Unconstrained File Upload Vulnerability

Worried this affects one of your servers?

DB-GPT allows uploading files without properly constraining the destination path, leading to arbitrary file writes.

DB-GPT builds the destination path for an uploaded skill from the multipart filename without validating it against the upload directory. This allows an attacker to write files outside the intended directory, including Python modules, leading to remote code execution.

Reference: CVE-2026-80104 on NVD

← Back to Security News