CVE-2024-10834 | eosphoros-ai db-gpt up to 0.6.0 RAG-Knowledge Endpoint os.path.join doc_file.filename file inclusion
A vulnerability was found in eosphoros-ai db-gpt up to 0.6.0. It has been rated as critical. Affected by this issue is the function os.path.join of the component RAG-Knowledge Endpoint. The manipulation of the argument doc_file.filename leads to file inclusion.
This vulnerability is handled as CVE-2024-10834. The attack may be launched remotely. There is no exploit available.