Skip to content
Critical RCE Vulnerabilities Discovered in DB-GPT AI Agent Platform

Critical RCE Vulnerabilities Discovered in DB-GPT AI Agent Platform

First seen 8 Oct 2026, 01:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 01:30 UTC

Two critical remote code execution (RCE) vulnerabilities, CVE-2026-51862 and CVE-2026-51869, were identified in version 0.8.0 of the DB-GPT AI agent platform, which serves as a data access layer for autonomous AI agents. CVE-2026-51862, with a CVSS score of 9.1, allows attackers to exploit a directory traversal flaw via the skill_upload endpoint. CVE-2026-51869, rated 9.8, results from a failure in the platform's sandbox mechanism, enabling code execution directly on the host filesystem when containerization tools are unavailable. The vulnerabilities pose a significant risk to organizations using this platform, as they compromise the security of sensitive enterprise data. No patches have been released for these vulnerabilities as of the latest updates. Organizations are advised to take immediate action to mitigate potential risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
CVE-2026-51862 and CVE-2026-51869 published
Two critical RCE vulnerabilities in DB-GPT platform were disclosed, affecting version 0.8.0.
Tech.Yahoo
Recent
No patches released
As of the latest updates, no patched versions have been listed for the identified CVEs.
Tech.Yahoo

More articles in this cluster (5)

Following this threat?

Track CVE-2026-51862 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions are affected?
Version 0.8.0 of the DB-GPT AI agent platform is affected by these vulnerabilities.
Are these vulnerabilities being exploited?
While there is a proof-of-concept available, there is no confirmed exploitation in the wild.
What should organizations do?
Organizations using DB-GPT 0.8.0 should assess their exposure and implement mitigations until patches are available.