Impact
A user can upload a skill via the /api/v1/skills/upload endpoint in DB‑GPT 0.7.5 and 0.8.0, and that skill can later be executed as part of the /api/v1/chat/react-agent flow. This allows an attacker to run arbitrary code within the DB‑GPT environment, potentially compromising data confidentiality, integrity, and availability. The weakness is a form of code injection where user supplied input is executed without proper isolation.
Affected Systems
Any deployment of DB‑GPT version 0.7.5 or 0.8.0 that exposes the skill upload API to untrusted users. No specific vendor or product version list beyond the affected DB‑GPT releases is provided.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the public exploitation likelihood is currently unknown. No CVSS score is provided; however, given that the uploaded skill is executed with the privileges of the DB‑GPT service, the potential impact is high. The attack vector is inferred to be remote and requires network access to the exposed API endpoints. If the application allows anonymous or privileged users to upload skills, exploitation is expected to be straightforward once the upload path is reachable.
OpenCVE Enrichment