CVE-2026-80104 | eosphoros-ai DB-GPT up to 0.8.0 Skill Upload agentic_data_api.py filename path traversal
A vulnerability, which was classified as critical, was found in eosphoros-ai DB-GPT up to 0.8.0. This impacts an unknown function of the file packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py of the component Skill Upload. Such manipulation of the argument filename leads to relative path traversal.
This vulnerability is listed as CVE-2026-80104. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.