CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)
This story is from 2026-08-31. It is preserved in the archive; the latest stories are on the live feed.
Originally published at HOL CVE-2026-80104: DB-GPT skill upload writes past the upload directory Two different unauthenticated path-traversal arbitrary file writes hit DB-GPT upload APIs. CVE-2026-80104 is the skill-upload multipart filename bug in agentic_data_api.py . Its sibling CVE-2026-73034 i…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-08-31 04:47 · DEV Community — AI
CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)