CVE-2026-80104

DB-GPT
6/100
exploitation likelihood
CVSS9.3
EPSS0.7%
KEVNone
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given and writes the request body to upload_dir / filename. A path composed with that operator discards the left operand when the right one is absolute and follows parent references otherwise, so a filename such as ../../../tmp/x or /tmp/x resolves outside th
EPSS 0.007 (probability of exploitation) · CVSS base 9.3
Public PoC / Exploit

No public PoC/exploit references indexed yet (Exploit-DB / nuclei). Newly-disclosed CVEs often have none — exploit publication lags disclosure.

References5