Vulnerability  ·  2026-10-01

DB-GPT skill upload-to-execution path leads to code execution in agent chat flow

VulnerabilityMedium impactGlobalCVE-2026-51866
Coordinated Ro1ME disclosure: the upload route accepts skill packages without blocking execution-capable content and the react-agent path will execute uploaded skills, yielding code execution in the DB-GPT service.
DB-GPT is an open LLM/agent data platform; unauthorized skill execution is a supply-chain-style code-execution path into database-adjacent AI services.
An attacker uploads a skill package containing a script through the real skill-upload route, then triggers its execution via the react-agent chat flow, running it in the service environment.
DB-GPT 0.7.5 and 0.8.0 (SkillManager upload → react-agent execution)
Update DB-GPT past 0.8.0; restrict skill upload to trusted users and validate skill packages.
NVDRo1ME PoC gist
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →