What happened
Coordinated Ro1ME disclosure: the upload route accepts skill packages without blocking execution-capable content and the react-agent path will execute uploaded skills, yielding code execution in the DB-GPT service.
Why it matters
DB-GPT is an open LLM/agent data platform; unauthorized skill execution is a supply-chain-style code-execution path into database-adjacent AI services.
Attack vector
An attacker uploads a skill package containing a script through the real skill-upload route, then triggers its execution via the react-agent chat flow, running it in the service environment.
Affected systems
DB-GPT 0.7.5 and 0.8.0 (SkillManager upload → react-agent execution)
Mitigation
Update DB-GPT past 0.8.0; restrict skill upload to trusted users and validate skill packages.