External risk intelligence

DB-GPT Directory Traversal Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-51864

The vulnerability exists in an API endpoint responsible for file uploads within a web application framework. Such API endpoints in data-centric applications are commonly exposed as part of the internet-facing web service to facilitate user interactions and data processing.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE concerns a critical vulnerability in DB-GPT, a tool used for interacting with large language models. The flaw allows attackers to upload files to unintended locations, potentially impacting data integrity and system security. The main concern is confirming relevance and exposure of this technology within our environment.

  • Unauthorized file uploads can bypass security controls.
  • Critical flaw impacts data integrity and system security.
  • Verify exposure and relevance within our systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted file upload request to an exposed API endpoint. This request, when processed by the vulnerable component, allows the attacker to write files to arbitrary locations on the server, bypassing intended storage boundaries. The successful exploitation could lead to unauthorized file creation, potentially impacting system integrity or enabling further malicious activity.

  • No authentication or user interaction needed.
  • Uploading a malicious file to an API.
  • Arbitrary file write, impacting system.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to write files to arbitrary locations on the server. This is possible when the file upload functionality is accessed by an unauthenticated remote attacker, potentially impacting system integrity and confidentiality.

  • Server file system.
  • Unauthenticated file upload.
  • Arbitrary file write may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in DB-GPT's file upload functionality requires immediate attention from teams responsible for application security and the specific application or platform owning the DB-GPT deployment. The first practical move is to identify all instances of DB-GPT, confirm their exposure to the network, assess business criticality, and then locate the accountable application owner to plan a risk-based remediation.

  • Identify and confirm DB-GPT instances.
  • Verify network exposure and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is DB-GPT and what is it used for?

DB-GPT is an open-source framework designed to interact with large language models. It provides infrastructure for developers to build data-centric applications, enabling capabilities like document analysis and database interaction. The software typically includes API components to handle user-provided files for these models, which is where this specific vulnerability resides.

How does CVE-2026-51864 lead to a directory traversal?

This vulnerability falls under the CWE-22 weakness class, commonly known as Path Traversal. It occurs when the software does not properly sanitize file paths provided during an upload. Because the API logic fails to restrict the destination to a designated folder, an attacker can manipulate the file path to write data outside the intended storage boundaries.

Do I need authentication to trigger this vulnerability?

No, the vulnerability in the python_file_upload API does not require authentication or user interaction. A remote attacker can send a specially crafted request directly to the vulnerable endpoint to execute the attack. It is important to note that simply visiting the application or browsing its interface does not trigger the bug; it specifically requires submitting a malicious file upload request.

Is my instance of DB-GPT at risk?

According to Halo Surface Signal, instances where this API endpoint is reachable over the internet are at higher risk. Because the affected component handles file uploads for data processing, it is often configured as an internet-facing service. You should determine if your deployment is accessible from outside your internal network, as this significantly increases the likelihood of a remote attempt.

How should I respond to this DB-GPT threat?

Start by auditing your infrastructure to locate all instances of DB-GPT v0.7.5 and v0.8.0. Once identified, confirm their network access and determine which applications depend on them. Coordinate with the application owners to assess the business impact and prioritize restricting access to these API endpoints until you can apply the necessary updates or security configuration changes.

References