CVE-2026-47668
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (POST /runners/start) allows remote code execution via code injection in the functionName parameter of JSON script assign commands. The functionName value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dbgate | dbgate | < 7.1.9 | affected |
Weaknesses
- CWE-20: CWE-20: Improper Input Validation
- CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-1188: CWE-1188: Insecure Default Initialization of Resource
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: total
Additional References
References
- https://github.com/dbgate/dbgate/security/advisories/GHSA-8v3q-9vmx-36vc
- https://github.com/dbgate/dbgate/releases/tag/v7.1.9
- https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/dbgate-unauth-rce.yaml
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.