CVE-2024-10834

CVSS 3.0 Score 9.1 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 73

Summary

CVE-2024-10834 is a newly disclosed vulnerability affecting the eosphoros-ai/db-gpt package version 0.6.0. This issue lies in the RAG-knowledge endpoint, which contains a flaw that enables arbitrary file writing. An attacker can exploit this vulnerability by setting the `doc_file.filename` parameter to an absolute path, thereby gaining the ability to write files to arbitrary locations on the target server. Potentially, this can result in the overwriting of critical system files or the creation of new SSH-key entries, posing a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share