CVE-2024-10833

CVSS 3.0 Score 9.1 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 22

Summary

CVE-2024-10833: The eosphoros-ai/db-gpt version 0.6.0 contains a critical vulnerability. An attacker can exploit the knowledge API's arbitrary file write vulnerability by constructing absolute paths using the user-controllable 'doc_file.filename' parameter. This issue allows the attacker to write files to any location on the target server through the endpoint designed for uploading files as 'knowledge'. The absolute path traversal weakness in the knowledge API poses a significant risk to the security of the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share