Description
In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.
Published: 2026-09-30
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

A user can upload a skill via the /api/v1/skills/upload endpoint in DB‑GPT 0.7.5 and 0.8.0, and that skill can later be executed as part of the /api/v1/chat/react-agent flow. This allows an attacker to run arbitrary code within the DB‑GPT environment, potentially compromising data confidentiality, integrity, and availability. The weakness is a form of code injection where user supplied input is executed without proper isolation.

Affected Systems

Any deployment of DB‑GPT version 0.7.5 or 0.8.0 that exposes the skill upload API to untrusted users. No specific vendor or product version list beyond the affected DB‑GPT releases is provided.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the public exploitation likelihood is currently unknown. No CVSS score is provided; however, given that the uploaded skill is executed with the privileges of the DB‑GPT service, the potential impact is high. The attack vector is inferred to be remote and requires network access to the exposed API endpoints. If the application allows anonymous or privileged users to upload skills, exploitation is expected to be straightforward once the upload path is reachable.

Generated by OpenCVE AI on September 30, 2026 at 23:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict the /api/v1/skills/upload endpoint to trusted administrators only.
  • Implement input validation or sandboxing for uploaded skills to prevent execution of malicious code.
  • Upgrade to a later DB‑GPT version once a patch that removes this execution path becomes available.

Generated by OpenCVE AI on September 30, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Skill Execution Leading to Potential Code Execution in DB‑GPT via Uploaded Skills
Weaknesses CWE-94

Wed, 30 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T20:59:27.479Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51866

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:17:12.483

Modified: 2026-09-30T21:17:12.483

Link: CVE-2026-51866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T23:15:14Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')