External risk intelligence

DB-GPT Skill Upload and Execution Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51866

The vulnerability affects API endpoints used for skill management and chat interactions. These functions are typical of web applications and AI agent platforms designed to be accessed via network requests, making them commonly exposed in production web-facing deployments.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in DB-GPT allows uploaded skills to be executed later through a chat interaction flow. This could potentially lead to unauthorized actions within the system, as it bypasses normal security checks for skill execution. The main concern at this time is confirming if this technology is in use and if it is exposed externally.

  • Malicious skills can run unexpectedly.
  • Affects AI platforms and interactions.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by first uploading a malicious skill via the designated upload API. Once the skill is uploaded, the attacker can then trigger its execution through a separate chat interaction endpoint, potentially leading to severe consequences due to the vulnerability's impact.

  • Publicly accessible upload API.
  • Chat interaction endpoint execution.
  • Arbitrary code execution and data compromise.

Live Threat

Current exploitation, exposure, and threat context

A critical vulnerability in DB-GPT could allow an unauthenticated attacker to execute arbitrary code when a skill uploaded through a specific API endpoint is later processed by the chat-react-agent flow. This could impact the confidentiality, integrity, and availability of the affected system.

  • System code execution.
  • Upload and execute malicious skill.
  • Compromise of the entire system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical vulnerability in DB-GPT's skill upload and execution flow likely impacts application owners and platform teams responsible for AI agent deployments. The immediate first step is to inventory all instances of DB-GPT, verify external reachability and business criticality, and identify the specific accountable owner for each instance to prioritize remediation efforts based on risk.

  • Application owners should own the issue.
  • Verify external exposure and business criticality.
  • Plan remediation based on risk and ownership.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is DB-GPT and what is it used for?

DB-GPT is an open-source framework designed to help developers build AI applications and agents powered by Large Language Models. It connects these models to private data and databases, providing features like data-driven chat interfaces, plugin management, and automated workflows. Users rely on it to create intelligent systems that can process information and perform tasks through specialized agents or uploaded skills.

What does CWE-94 mean regarding CVE-2026-51866?

CWE-94 refers to Improper Control of Generation of Code, commonly known as Code Injection. In the context of CVE-2026-51866, this means the application fails to safely handle a user-provided file or script—in this case, a 'skill'—allowing it to be treated as executable code. Because the system lacks proper validation, an uploaded file can be triggered to run unexpectedly, effectively letting an attacker force the system to perform unauthorized actions.

How does an attacker trigger this vulnerability?

The attack occurs in two stages. First, an attacker uses the /api/v1/skills/upload route to place a malicious skill onto the system. Second, they trigger that skill via the /api/v1/chat/react-agent endpoint. Simply uploading the file is not enough; the vulnerability specifically relies on the system later processing that malicious input through the chat interaction flow. If the chat flow is not utilized, the uploaded file remains inert.

Why should I be concerned if my DB-GPT instance is internet-facing?

According to Halo Surface Signal, this vulnerability is particularly relevant to internet-facing deployments because the affected API endpoints are standard for web-based AI platforms. When a system is reachable via the network, an unauthorized actor does not need internal access to upload and execute malicious code. If your instance is exposed to the public internet, the barrier for an attacker to reach these skill management and chat functions is significantly lowered.

What are the first steps to secure my DB-GPT deployment?

Begin by creating an accurate inventory of all DB-GPT instances running in your environment. For each instance, confirm whether it is accessible from the public internet and assess its business importance. Identify the teams or individuals responsible for these specific deployments to ensure clear ownership. Once these are mapped, you can prioritize remediation efforts based on the level of risk each instance presents to your infrastructure.

References