CVE-2026-47668

Summary

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (POST /runners/start) allows remote code execution via code injection in the functionName parameter of JSON script assign commands. The functionName value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.

Affected Software

VendorProductVersion RangeStatus
dbgatedbgate< 7.1.9affected

Weaknesses

  • CWE-20: CWE-20: Improper Input Validation
  • CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
  • CWE-1188: CWE-1188: Insecure Default Initialization of Resource

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: total

Additional References

References