Tech.Yahoo Critical RCE Vulnerabilities Discovered in DB-GPT AI Agent Platform
Article Content
- •Two critical RCE vulnerabilities identified in DB-GPT platform.
- •CVE-2026-51862 allows directory traversal; CVE-2026-51869 enables sandbox escape.
- •No patches available; organizations using version 0.8.0 are at risk.
Two critical remote code execution (RCE) vulnerabilities, CVE-2026-51862 and CVE-2026-51869, were identified in version 0.8.0 of the DB-GPT AI agent platform, which serves as a data access layer for autonomous AI agents. CVE-2026-51862, with a CVSS score of 9.1, allows attackers to exploit a directory traversal flaw via the skill_upload endpoint. CVE-2026-51869, rated 9.8, results from a failure in the platform's sandbox mechanism, enabling code execution directly on the host filesystem when containerization tools are unavailable. The vulnerabilities pose a significant risk to organizations using this platform, as they compromise the security of sensitive enterprise data. No patches have been released for these vulnerabilities as of the latest updates. Organizations are advised to take immediate action to mitigate potential risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-51862 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions are affected?
Are these vulnerabilities being exploited?
What should organizations do?
Continue Reading
Surge in Cyberattacks Targeting UK Education Sector UK academic institutions are facing a significant increase in cyberattacks, with SonicWall reporting over 19.3 million medium and high-severity intrusion attempts in 2026, a 67% rise from 2025. The education sector accounted for 87% of these attacks, primarily targeting web-facing infrastructure. Path traversal and…