CVE-2024-10830

CVSS 3.0 Score 8.2 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 22

Summary

CVE-2024-10830 is a newly disclosed Path Traversal vulnerability that affects the eosphoros-ai/db-gpt version 0.6.0. The issue resides in the `/v1/resource/file/delete` API endpoint where the `file_key` parameter is not adequately sanitized. An attacker can exploit this flaw by providing invalid input for the `file_key` parameter, leading them to delete any file on the server. This vulnerability poses a significant risk as it allows unauthorized file deletion, potentially resulting in data loss or system instability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share