Dbgate vulnerabilities
7 known vulnerabilities affecting dbgate/dbgate.
Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5
Vulnerabilities
Page 1 of 1
CVE-2026-47670P2CRITICALCVSS 9.4PoCfixed in 7.1.92026-07-23
CVE-2026-47670 [CRITICAL] CWE-77 CVE-2026-47670: DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially by
nvd
CVE-2026-47669P2CRITICALCVSS 9.3fixed in 7.1.92026-07-23
CVE-2026-47669 [CRITICAL] CWE-22 CVE-2026-47669: DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` funct
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes files anywhere on the filesystem. In the default Docker deployment, Db
ghsanvd
CVE-2026-48017P2HIGHCVSS 8.8fixed in 7.1.92026-06-15
CVE-2026-48017 [HIGH] CWE-94 CVE-2026-48017: DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reade
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no special permissions required) can inject arbitrary Ja
nvd
CVE-2026-85176P3HIGHCVSS 8.8≤ 7.2.62026-09-03
CVE-2026-85176 [HIGH] CWE-73 CVE-2026-85176: DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to
DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.
nvd
CVE-2025-50184P3HIGHCVSS 7.1fixed in 6.4.3-beta.82025-07-26
CVE-2025-50184 [HIGH] CWE-29 CVE-2025-50184: DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vul
DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted to the intended uploads directory. As a result, the endpoint that lists files within the upload directory can be manipulated to access arbitrary files on the system. By
nvd
CVE-2025-50185P3HIGHCVSS 7.0≤ 6.6.02025-07-26
CVE-2025-50185 [HIGH] CWE-29 CVE-2025-50185: DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized f
DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to insufficient validation of file paths and types. A user with application-level access can retrieve data from arbitrary files on the system, regardless of their location or file type. The plugin fails to enforce proper checks on content
nvd
CVE-2026-34725P3HIGHCVSS 8.2v>= 7.0.0, < 7.1.52026-04-02
CVE-2026-34725 [HIGH] CWE-79 CVE-2026-34725: DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS
DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization. In the web UI this allows script execution in another user's browser; in the Electron desktop app this can escalate to local code ex
nvd