Sceawere

Vulnerability Detail

CVE-2026-51866UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DB-GPT Arbitrary Skill Execution

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
22h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-30T21:17:12.483Z",
  "pubdate": "2026-09-30T21:17:12.483Z",
  "executiveSummary": "DB-GPT versions 0.7.5 and 0.8.0 contain a critical vulnerability where an authenticated user can perform an arbitrary code execution attack by uploading and subsequently invoking malicious skills.\nThe vulnerability type is categorized as Improper Access Control and Arbitrary Code Execution. An attacker with the ability to interface with the skill upload API can supply a crafted skill file, which the application then allows to be executed within the context of the chat/react-agent flow.\nThis flaw allows a malicious actor to achieve remote code execution on the underlying server hosting the DB-GPT instance.\nThe risk is severe, as it bypasses intended sandboxing or validation mechanisms for agent-based execution. Successful exploitation does not require advanced post-exploitation techniques, as the product inherently executes the uploaded logic once triggered via the chat interface.\nThe vulnerability impacts the integrity and confidentiality of the entire host system, as executed skills inherit the runtime permissions of the DB-GPT service. Organizations deploying these versions are at significant risk of unauthorized server-side manipulation.",
  "technicalDetails": "The vulnerability resides in the interaction between the /api/v1/skills/upload route and the /api/v1/chat/react-agent execution flow. The root cause is the lack of strict validation and secure sandboxing of uploaded skill assets before they are registered and indexed as callable functions within the agent's environment.\nIn the affected versions, when a skill is uploaded, the application persists the file to the local filesystem or a defined skill directory. The application fails to perform sufficient integrity checks, malicious payload scanning, or execution environment isolation for these user-supplied artifacts.\nThe attack flow follows a predictable sequence: First, the attacker authenticates to the DB-GPT platform. Second, the attacker utilizes the /api/v1/skills/upload endpoint to transmit a malicious Python script or configuration file designed to execute arbitrary OS commands upon invocation. Third, the attacker initiates a conversation via the /api/v1/chat/react-agent endpoint.\nWhen the agent receives a request that triggers the newly uploaded skill, the DB-GPT backend dynamically imports and executes the logic defined in the skill file. Because the application trusts the contents of the upload directory, the arbitrary code is executed with the same privileges as the DB-GPT backend service process.\nThis behavior is particularly dangerous because the /api/v1/chat/react-agent flow is designed to facilitate autonomous agent decision-making, which encourages the execution of tools to solve user queries. By successfully uploading a malicious tool, the attacker effectively transforms the AI agent into a proxy for arbitrary system operations, including data exfiltration, local file access, or lateral movement within the network.\nThere are no apparent restrictions on the logic that can be defined within the uploaded skills. The absence of a robust execution policy means that any code reachable within the Python runtime environment can be invoked. The vulnerability persists across versions 0.7.5 and 0.8.0, and the exploitability depends solely on the ability to reach the API endpoints and have sufficient permissions to perform uploads."
}
CVE-2026-51866: DB-GPT Arbitrary Skill Execution (CRITICAL Severity, CVSS: 9.8) | Sceawere