Fixed in June, Numbered in September: DB-GPT’s Two Critical RCEs and the Advisory That Names No Fixed Version
DB-GPT sits in one of the most privileged positions in the agentic stack: it is the bridge between autonomous agents and enterprise data — text-to-SQL, retrieval, and generated code execution against databases and knowledge bases. Two critical CVEs published on 30 September 2026 show what happens when that bridge is built on trusting defaults. CVE-2026-51862 (CVSS 3.1 9.1, CWE-22) is a path traversal in the skill-upload endpoint that allows writing files outside the workspace. CVE-2026-51869 (CVSS 3.1 9.8, CWE-284) is a sandbox that silently stops being a sandbox: when no container runtime is available, it falls back to executing submitted code directly on the host.
Here is the part operators most need to hear: both flaws were reported in the spring, both were fixed on the main branch before the summer, and the CVE records still do not name a fixed version. Anyone triaging from the advisories alone cannot tell which release is safe. So we checked the release tags ourselves.
Two reports from one researcher, two layers of the same trust assumption
Both findings come from researcher Ro1ME, and they read as companion pieces. Issue #3026, opened 20 April 2026, documents the traversal: the skill_upload handler in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes the multipart filename and joins it straight onto the upload directory — target_path = upload_dir / filename — so a filename like ../../../../../../tmp/backdoor.py lands outside the intended boundary. From there the reporter’s escalation logic is straightforward: overwrite a Python module or a configuration file the process loads, and an arbitrary file write becomes code execution.
Issue #3082, opened 22 May 2026, documents the sandbox fallback. In the tested snapshot, SANDBOX_RUNTIME defaulted to "local", and RuntimeFactory.create() returned LocalRuntime() whenever the preference was local or no container runtime was selected or available. No warning, no fail-closed behaviour. Ro1ME verified it end to end through a live FastAPI sandbox session — /api/connect followed by /api/execute — and confirmed the observed runtime was LocalRuntime, with a benign marker file proving the API path reached host-side execution.
The shared defect is availability prioritised over security: the platform assumes the environment is safe unless told otherwise, in exactly the layer whose job is to contain untrusted, agent-generated code. We covered the same failure shape last week in LMCache’s unauthenticated /run_script endpoint — a code-execution surface whose sandbox does not hold. The DB-GPT variant is arguably worse, because the fallback is silent: an operator who deployed with Docker in mind but lost the daemon, or never had one, gets host execution with no signal that containment is gone.
A note on “unauthenticated”
Both NVD vectors score privileges-required none and user-interaction none over the network. That deserves one careful qualification. Ro1ME’s traversal proof of concept sends the upload with a bearer token, and the handler does resolve the caller through get_user_from_headers — so the reporter demonstrated the flaw as an authenticated user, while the CVE record scores it as requiring no privileges. CISA’s SSVC assessment (added 7 October 2026) marks both CVEs exploitation proof-of-concept, automatable yes, technical impact total.
The honest reading: the traversal is reachable by any account the deployment hands a token to — and DB-GPT deployments routinely mint those for application users — while the sandbox issue is a design default that needs no credential at all to be dangerous once the API is reachable. Do not let the scoring nuance become an excuse. Treat every DB-GPT 0.8.0 instance as exposed until upgraded.
The fixes shipped in June; the CVEs arrived in September; the advisories name nothing
This is the timeline that matters, and every date below is verified against the repository and the registries, not inferred:
- 27 March 2026 —
dbgpt0.8.0 uploaded to PyPI. This is the version both CVE records name as affected, and it predates both fixes. - 21 May 2026 — PR #3065 merged to main, closing #3026: uploaded skill filenames are validated before any write, rejecting absolute paths, traversal sequences, Windows separators, null bytes, and special dot names.
- 17 June 2026 — PR #3092, “fix(sandbox): require local runtime opt-in,” merged to main, closing #3082.
- 18 June 2026 —
dbgpt0.8.1 uploaded to PyPI, one day after the sandbox fix merged. - 26 August 2026 —
dbgpt0.8.2 uploaded to PyPI; still the latest release. - 30 September 2026 — both CVE records published. NVD’s affected block carries no vendor and no version range, and no vendor security advisory names a fixed version.
We did not stop at the dates. We retrieved the affected files at the release tags. At v0.8.0, the sandbox config reads SANDBOX_RUNTIME = os.getenv("SANDBOX_RUNTIME", "local") — the silent default, vulnerable. At v0.8.1, the default is gone: the variable is read without a local fallback alongside a SANDBOX_ALLOW_LOCAL_RUNTIME opt-in gate. Likewise, the upload handler at v0.8.1 carries the filename-validation helper and absolute-path checks that are entirely absent at v0.8.0.
So the remediation answer the advisories fail to give is: 0.8.0 is affected by both CVEs; 0.8.1 contains both fixes; 0.8.2 is the current release and the version to run. The uncomfortable corollary is the three-month window — fixes on main in May and June, CVE numbers in late September — during which the only public signal was two GitHub issues. Silent fixes protect nobody who does not watch the commit log.
What to do
- Inventory DB-GPT versions before anything else. Anything on 0.8.0 is affected by both CVEs. Upgrade to 0.8.2; 0.8.1 is the first tag carrying both fixes, but there is no reason to stop there.
- Audit for the traversal, not just the version. The skill-upload flaw writes attacker-named files wherever the process can write. On any 0.8.0 host, look for files outside the
pilot/tmpworkspace and the skills directory with unexpected modification times — especially Python modules and configuration files the service loads. - Verify your sandbox backend explicitly. After upgrading, confirm the runtime your deployment actually selects: if no container runtime is present and you have not set the local-runtime opt-in, execution must now refuse rather than silently proceed. Test that refusal — the whole point of #3082 is that nobody noticed the fallback.
- Treat the API surface as the trust boundary. The agent-data endpoints accept uploads and code for execution by design. They belong behind authentication you control and network policy that assumes compromise, not on a segment where any holder of a token — or any route to the sandbox API — inherits host execution.
- Rotate what a compromised bridge could reach. DB-GPT holds database credentials by design. On any host that ran 0.8.0 with these endpoints reachable, rotate database credentials and any API keys in the process environment, and review database query logs for unexpected statements.
- Watch the commit log, not just the advisory feed. Both fixes landed months before the CVEs. For fast-moving agent frameworks, release notes and merged security PRs are earlier signals than CVE publication — NVD still lists both records as Deferred enrichment.
Verification note: we pulled both NVD records directly (CVE-2026-51862, CVSS 3.1 9.1, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, CWE-22, published 2026-09-30T21:17:12Z; CVE-2026-51869, CVSS 3.1 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-284, published 2026-09-30T21:17:12Z; both vulnStatus Deferred, both last modified 2026-10-07 with CISA SSVC exploitation:poc / automatable:yes / technicalImpact:total). We read issues #3026 (opened 20 April 2026) and #3082 (opened 22 May 2026) and the merged fix PRs #3065 (merged 21 May 2026) and #3092 (merged 17 June 2026; #3086 remains open and superseded) via the GitHub web and API surfaces. We queried the PyPI JSON API for release upload dates (0.8.0 on 2026-03-27, 0.8.1 on 2026-06-18, 0.8.2 on 2026-08-26, latest) and retrieved the affected source files at tags v0.8.0 and v0.8.1, confirming the silent "local" default and the missing filename validation at v0.8.0 and the opt-in gate plus validation helper at v0.8.1. We did not deploy DB-GPT and did not attempt exploitation.
Sources:
- NVD — CVE-2026-51862, DB-GPT skill_upload directory traversal (CVSS 3.1 9.1, CWE-22)
- NVD — CVE-2026-51869, DB-GPT sandbox silent LocalRuntime fallback (CVSS 3.1 9.8, CWE-284)
- eosphoros-ai/DB-GPT #3026 — path traversal in skill_upload (Ro1ME, 20 April 2026)
- eosphoros-ai/DB-GPT #3082 — sandbox API silently falls back to LocalRuntime (Ro1ME, 22 May 2026)
- eosphoros-ai/DB-GPT #3065 — filename validation fix, merged 21 May 2026
- eosphoros-ai/DB-GPT #3092 — require local runtime opt-in, merged 17 June 2026
- PyPI — dbgpt release history (0.8.0 March 2026, 0.8.1 June 2026, 0.8.2 August 2026)