Impact
A path traversal vulnerability was identified in the createLink function of the Archive Link Creation component of dbgate. By manipulating the linkedFolder parameter, an attacker can construct filesystem paths that escape the intended directory boundaries. This flaw allows the attacker to read arbitrary files on the server, potentially exposing sensitive configuration files or user data. The vulnerability is remote, meaning an adversary can trigger it over the network without needing local credentials.
Affected Systems
The flaw exists in dbgate versions up to and including 7.3.1. The vulnerable code resides in packages/api/src/controllers/archive.js. Even though dbgate is a single open‑source project, any deployment that has this component exposed over a network is subject to the risk, especially if the archive endpoints are publicly accessible.
Risk and Exploitability
With a CVSS score of 6.9, the vulnerability carries a moderate to high risk. The attack vector is remote, and the exploit has been publicly disclosed, making it likely to be used once a vendor fix is released. Because the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the current likelihood of exploitation is uncertain, but the lack of a response from the vendor raises concerns about rapid remediation.
OpenCVE Enrichment