Description
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

A path traversal vulnerability was identified in the createLink function of the Archive Link Creation component of dbgate. By manipulating the linkedFolder parameter, an attacker can construct filesystem paths that escape the intended directory boundaries. This flaw allows the attacker to read arbitrary files on the server, potentially exposing sensitive configuration files or user data. The vulnerability is remote, meaning an adversary can trigger it over the network without needing local credentials.

Affected Systems

The flaw exists in dbgate versions up to and including 7.3.1. The vulnerable code resides in packages/api/src/controllers/archive.js. Even though dbgate is a single open‑source project, any deployment that has this component exposed over a network is subject to the risk, especially if the archive endpoints are publicly accessible.

Risk and Exploitability

With a CVSS score of 6.9, the vulnerability carries a moderate to high risk. The attack vector is remote, and the exploit has been publicly disclosed, making it likely to be used once a vendor fix is released. Because the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the current likelihood of exploitation is uncertain, but the lack of a response from the vendor raises concerns about rapid remediation.

Generated by OpenCVE AI on September 28, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade dbgate to the latest release that fixes the createLink path traversal or apply a community‑provided patch if available.
  • If an update cannot be applied immediately, restrict remote access to the /archive/createLink endpoint or enforce authentication so that only trusted users can invoke it.
  • Implement server‑side input validation that removes or rejects traversal sequences (such as ".." or absolute paths) from the linkedFolder parameter to ensure that references remain within the authorized directory.

Generated by OpenCVE AI on September 28, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title dbgate Archive Link Creation archive.js createLink path traversal
First Time appeared Dbgate
Dbgate dbgate
Weaknesses CWE-22
CPEs cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:*
Vendors & Products Dbgate
Dbgate dbgate
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T12:47:06.737Z

Reserved: 2026-09-27T17:01:07.066Z

Link: CVE-2026-101066

cve-icon Vulnrichment

Updated: 2026-09-28T12:47:01.107Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T13:17:20.080

Modified: 2026-09-28T13:17:20.253

Link: CVE-2026-101066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T14:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')