CVE-2026-51862: DB-GPT DB-GPT vulnerability
Published Sep 30, 2026
·Updated
DB-GPT 0.8.0 contains directory traversal in skillupload (packages/dbgpt-app/src/dbgptapp/openapi/apiv1/agenticdataapi.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
Affected Software
1 affected component
DB-GPT DB-GPT=0.8.0
Event History
Sep 30, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
Description