Critical RCE Vulnerabilities Discovered in DB-GPT AI Agent Platform
Two severe remote code execution flaws in version 0.8.0 of the DB-GPT platform highlight growing security risks at the data access layer.
Critical RCE Vulnerabilities Discovered in DB-GPT AI Agent Platform
Two severe remote code execution flaws in version 0.8.0 of the DB-GPT platform highlight growing security risks at the data access layer.

Platform Vulnerabilities Exposed
The DB-GPT AI agent platform functions as an intermediary layer linking autonomous AI agents with structured data sources such as databases and knowledge bases. According to forkast.news, version 0.8.0 of the platform contains two unauthenticated, network-exploitable remote code execution vulnerabilities identified as CVE-2026-51862 and CVE-2026-51869.
CVE-2026-51862 carries a CVSS score of 9.1 and represents a directory traversal flaw within the skill_upload endpoint, permitting remote attackers to write files outside intended workspace boundaries. An even more critical flaw, CVE-2026-51869, holds a CVSS score of 9.8 and arises from a failure in the system's sandbox mechanism when containerization tools are unavailable.
Sandbox Mechanism Failures
When tools like Docker, Podman, or Nerdctl are absent, the DB-GPT platform silently falls back to a LocalRuntime environment without issuing a warning or implementing a fail-closed policy. This behavior leads directly to code execution on the host filesystem.
Research cited in GitHub issue #3082 by Ro1ME demonstrated that uploading a CSV file to the web interface and requesting analysis forces an AI agent to execute code on the host. Organizations currently deploying version 0.8.0 are advised by reports to treat installations as compromised and prioritize isolation or migration.
Broader Infrastructure Implications
The security gaps in DB-GPT reflect a wider pattern of trust-through-defaults issues across enterprise technology layers. Similar architectural risks have emerged in network infrastructure, such as recent vulnerabilities discovered in Cisco Nexus 9000 switches and enterprise software.
As the industry addresses the expansion of agentic security risks, various vendors are introducing runtime safety mechanisms, sandboxing tools, and identity frameworks to protect autonomous workflows and protocol stacks.