Back Forkast.News DB-GPT AI Agent Platform: Two Critical RCE CVEs at the Agent Data Access Layer
DB-GPT functions as a critical intermediary layer, bridging autonomous AI agents with structured data sources like databases and knowledge bases. By design, this platform acts as the gatekeeper for sensitive enterprise information, facilitating complex operations such as text2sql, RAG, and autonomous code execution. When this bridge is compromised, the security model of the entire agentic workflow collapses, as downstream database interactions inherit the exposure of the orchestration layer. Two unauthenticated, network-exploitable remote code execution (RCE) vulnerabilities in version 0.8.0 of this platform, identified as CVE-2026-51862 and CVE-2026-51869 , demonstrate how easily this gatekeeper role can be subverted.
The vulnerabilities present a direct threat to the underlying infrastructure of any organization utilizing the tool. CVE-2026-51862, carrying a CVSS score of 9.1, is a directory traversal flaw located within the skill_upload endpoint. This allows a remote attacker to write files outside of the intended workspace boundaries. Even more critical is CVE-2026-51869, which holds a CVSS score of 9.8. This flaw stems from a failure in the platform’s sandbox mechanism. When containerization tools such as Docker, Podman, or Nerdctl are unavailable, the system silently falls back to a LocalRuntime environment. Because the platform fails to implement a fail-closed policy or issue a warning, it proceeds to execute code directly on the host filesystem.
The root cause of this sandbox escape is located in the RuntimeFactory.create() method, which defaults the SANDBOX_RUNTIME configuration to ‘local’. A proof-of-concept documented in GitHub issue #3082 by researcher Ro1ME confirms the severity of this design. By uploading a CSV file to the web interface and requesting analysis, an attacker can force an AI agent to generate and execute code on the host, successfully creating a marker file at /tmp/dbgpt_web_unsandboxed.txt. This confirms that the platform prioritizes availability over security, assuming the environment is inherently secure unless otherwise specified.
This incident serves as a definitive example of the trust-through-defaults pattern at the agent data access layer. Much like the Cisco Nexus 9000 vulnerability , where default configurations created systemic risk at the network layer, DB-GPT’s silent fallback to a local runtime creates an equivalent risk at the data access layer. The platform’s design choice effectively bypasses the security controls that developers and IT decision-makers assume are in place. This trend of agentic security risks is expanding, drawing parallels to the Agent Identity Layer Risk and the DIVD/Zammad incident , which marked one of the first documented agentic AI-powered attacks against a security organization.
As of the latest updates, no patched versions have been listed in the official advisories for these CVEs, although the latest release on PyPI is 0.8.2. Organizations currently deploying DB-GPT 0.8.0 should treat their installations as compromised and prioritize immediate isolation or migration to a more secure architecture. The absence of a patch underscores the necessity for security professionals to rigorously scrutinize the default configurations of any AI-native platform before integrating it into production environments. Given the platform’s significant deployment footprint, stemming from its status as an open-source tool with approximately 10,000 GitHub stars, the failure to secure these defaults leaves a substantial portion of the agentic ecosystem exposed to unauthorized data access and system control.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
