PatchSiren

eosphoros-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL eosphoros-ai CVE published 2026-08-25

CVE-2026-80104

A critical vulnerability, CVE-2026-80104, exists in DB-GPT, allowing unauthenticated remote attackers to write arbitrary files and execute code on the server. The vulnerability arises from improper handling of file uploads, enabling attackers to bypass directory constraints and write to any path the server process can access. This can lead to arbitrary code execution when a malicious Python module is impo [truncated]

CRITICAL eosphoros-ai CVE published 2026-08-11

CVE-2026-73034

CVE-2026-73034 is a critical unauthenticated path traversal vulnerability in DB-GPT v0.8.1 that allows remote attackers to write arbitrary files to any location on the server. This vulnerability is particularly concerning as it can lead to remote code execution by writing attacker-controlled content to sensitive locations such as Python startup hooks, cron directories, or agent scripts.