CVE-2024-10830

HIGH

db-gpt 0.6.0 - Path Traversal and Arbitrary File Deletion via File Key Parameter

Title source: llm
STIX 2.1

Description

A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability allows an attacker to delete any file on the server by manipulating the `file_key` parameter. The `file_key` parameter is not properly sanitized, enabling an attacker to specify arbitrary file paths. If the specified file exists, the application will delete it.

References (1)

Core 1
Core References

Scores

CVSS v3 8.2
EPSS 0.0024
EPSS Percentile 46.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
dbgpt/db-gpt 0.6.0
pypi/dbgpt 0PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026