CVE-2026-51866 Details
Description
In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.
A remote code execution vulnerability exists in DB-GPT versions 0.7.5 and 0.8.0. Skills uploaded via the /api/v1/skills/upload endpoint can be executed through the /api/v1/chat/react-agent flow. The execution is handled by the SkillManager.execute_skill_script_file function, which reads the uploaded script content, converts it into executable Python code, and runs it on the host system using asyncio.create_subprocess_exec, leading to unauthorized script execution.
Users can update to DB-GPT version 0.8.1, which restricts the execution of personal skill scripts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Ro1ME/f8f5b730a4000684d3a92a67f82ee03c | [email protected] | ExploitTechnical Description |
| https://github.com/eosphoros-ai/DB-GPT/issues/3047 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| DB-GPT | 0.7.5 (semver) 0.8.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion