DB - GPT AI Proxy Platform: Two Critical RCE Vulnerabilities Affect the Data Access Layer
2026-10-08 08:11:22
According to CoinMeta, the DB - GPT AI proxy platform has identified two critical remote code execution (RCE) vulnerabilities at its data access layer. These vulnerabilities allow attackers to use the platform as a intermediary for sensitive corporate information, enabling them to perform complex operations such as text manipulation and autonomous code execution. The two vulnerabilities in version 0.8.0 are CVE-2026-51862 and CVE-2026-51869, with the former having a severity score of 9.1 and the latter of 9.8, both posing a direct threat to organizations using this tool. CVE-2026-51862 allows remote attackers to write files outside the designated workspace boundaries, while CVE-2026-51869 stems from a failure in the platform's sandbox mechanism, resulting in code being executed directly on the host file system. No patch versions have been released yet; organizations using DB-GPT 0.8.0 should consider their systems compromised and prioritize isolating them or migrating to a more secure architecture.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.