CVE-2026-51869 Details
Description
DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
A vulnerability in DB-GPT version 0.8.0 allows the sandbox API to default to LocalRuntime, executing code on the host machine. This issue arises when container runtimes are unavailable, leaving untrusted code execution without proper isolation. The vulnerability can be exploited through the DB-GPT Web UI, where uploaded data files can trigger arbitrary code execution on the host.
Users can update to DB-GPT version 0.8.1, which includes a fix requiring explicit opt-in for LocalRuntime, preventing unsandboxed execution by default.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Ro1ME/884fbbd589998b81fa05c20ac205569f | [email protected] | ExploitTechnical Description |
| https://github.com/eosphoros-ai/DB-GPT/issues/3082 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| DB-GPT | 0.8.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion