External risk intelligence

DB-GPT Sandbox API Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51869

DB-GPT is a framework designed to build AI applications and services. The vulnerability exists within its sandbox API, which is a component typically exposed to process external user requests. As an API-based service intended for integration and interaction, it is commonly deployed in a network-reachable or internet-facing configuration to function as an application backend.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in DB-GPT's sandbox API, allowing for the silent execution of code on the host system. This issue arises when the API unexpectedly reverts to a less secure runtime environment, potentially exposing sensitive operations. The main concern is confirming relevance and exposure for affected systems.

  • API can run unauthorized code.
  • External interaction means potential for wide impact.
  • Assess system relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit a flaw in DB-GPT's sandbox API, which is accessible over the network without authentication. When the API fails to properly isolate code execution, it can allow malicious commands to run directly on the host system. This could lead to a complete compromise of the server.

  • Accessible over the network without authentication.
  • Sandbox API falls back to LocalRuntime.
  • Complete server compromise is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary code on the host system by sending specially crafted requests to the sandbox API. The system's data and services could be compromised when the sandbox API fails to properly isolate code execution and instead reverts to running it locally on the host.

  • Host system code execution.
  • Unauthenticated API requests.
  • Compromised system data and services.

Operational Fix

Recommended remediation, mitigation, and detection steps

The discovery that DB-GPT's sandbox API can fall back to LocalRuntime and execute host code indicates a critical risk for application owners and platform teams. The immediate first step is to identify all instances of the affected technology, determine their network reachability and business criticality, and then locate the accountable owner to plan remediation based on assessed risk.

  • Application and platform teams should own.
  • Verify external API reachability and criticality.
  • Plan remediation based on exposure risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is DB-GPT and what is its role?

DB-GPT is an open-source framework designed to help developers build artificial intelligence applications and data-driven services. It often acts as an application backend, providing a sandbox API that processes data and manages how AI models interact with host systems.

What does CWE-284 mean for CVE-2026-51869?

CWE-284 refers to Improper Access Control. In the context of CVE-2026-51869, this means the software fails to properly restrict or authorize commands sent to the sandbox API. Instead of keeping execution contained, the system incorrectly grants the API power to run code directly on the host machine.

How does this vulnerability get triggered?

An attacker triggers this by sending unauthenticated requests to the sandbox API. The vulnerability occurs when the API fails to use its intended secure sandbox and silently falls back to a LocalRuntime environment. Standard requests that successfully stay within the isolated sandbox environment do not trigger this specific host-level execution flaw.

Do I need to worry if my DB-GPT instance is internal?

Halo Surface Signal indicates that because DB-GPT functions as an API-based service, it is often deployed in network-reachable or internet-facing configurations. While internet-facing instances are at higher risk, any internal system reachable by other users or compromised services on your network could also be targeted to execute unauthorized host commands.

Why should I identify my DB-GPT instances now?

Because this flaw allows unauthenticated code execution on the host, you need to map every instance to determine which systems are exposed to the network. Once you have a complete inventory, you can prioritize remediation for the most critical or internet-accessible services to prevent unauthorized system access.

References